<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="2967710.xsl"?>
<?xml-stylesheet type="text/css" href="2967708.css"?>
<cvrf:cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle Critical Patch Update Advisory - October 2020 - Oracle CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle Critical Patch Update Advisory</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>CPUOct2020</ID>
      </Identification>
      <Status>Final</Status>
      <Version>6</Version>
      <RevisionHistory>
         <Revision>
            <Number>6</Number>
            <Date>2020-12-08T13:50:00-07:00</Date>
            <Description>Added a note for CVE-2020-14871.</Description>
         </Revision>
      </RevisionHistory>
      <InitialReleaseDate>2020-10-20T13:00:00-07:00</InitialReleaseDate>
      <CurrentReleaseDate>2020-12-08T13:50:00-07:00</CurrentReleaseDate>
   </DocumentTracking>
   <DocumentNotes>
      <Note Audience="All" Ordinal="1" Title="Summary" Type="Summary" xml:lang="en">This document contains descriptions of Oracle product security vulnerabilities which have had security patches released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including security patch distribution information can be found at the Oracle sites referenced in this document.</Note>
   </DocumentNotes>
   <DocumentDistribution>This document is published at: https://www.oracle.com/a/tech/docs/cpuoct2020cvrf.xml</DocumentDistribution>
   <DocumentReferences>
      <Reference Type="External">
         <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
   <Acknowledgments>
      <Acknowledgment>
         <Name>0rich1 Ant Security FG Lab</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Aaron Carreras</Name>
         <Organization>FireEye</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Abdulrahman Ahmed</Name>
         <Organization>Abdulrahman Ahmed</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Abdulrahman Nour</Name>
         <Organization>Redforce</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Abhishek Morla</Name>
         <Organization>Abhishek Morla</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Adam Willard</Name>
         <Organization>Adam Willard</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Adam Willard</Name>
         <Organization>Raytheon Foreground Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Adarsh VS Mannarakkal</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ahmed Elhady Mohamed</Name>
         <Organization>Ahmed Mohamed</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ahmed Elmalky</Name>
         <Organization>Ahmed Elmalky</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ahmed Omer Morve</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Akshay Gaikwad</Name>
         <Organization>Akshay Gaikwad</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alessandro Bosco</Name>
         <Organization>TIM S.p.A</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alex Munene</Name>
         <Organization>Alex Munene</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alexander Kornbrust</Name>
         <Organization>Red Database Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alisha Sheikh</Name>
         <Organization>Alisha Sheikh</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alves Christopher of Telecom Nancy</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ammarit Thongthua</Name>
         <Organization>Secure D Center Cybersecurity Team</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Amy Tran</Name>
         <Organization>Amy Tran</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Andrej Simko</Name>
         <Organization>Accenture</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Anil Bhatt</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Anonymous researcher working with Trend Micro's Zero Day Initiative</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Syed Muhammad Asim</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ayan Saha</Name>
         <Organization>Ayan Saha</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Badal Sardhara</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Bindiya Sardhara</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Shubham Kalaria</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Bui Duong from Viettel Cyber Security</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Chi Tran</Name>
         <Organization>Chi Tran</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Shivang Trivedi</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Anurag Kumar Rawat (A1C3VENOM)</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Damian Bury</Name>
         <Organization>Damian Bury</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Danny</Name>
         <Organization>Danny</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Darragh Duffy</Name>
         <Organization>Darragh Duffy</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>David Wilkins</Name>
         <Organization>David Wilkins(au)</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Dhiraj Mishra</Name>
         <Organization>Dhiraj Mishra</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Eddie Zhu of BEIJING DBSEC TECHNOLOGY CO., LTD</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Edoardo Predieri</Name>
         <Organization>TIM S.p.A</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Fabio Minarelli</Name>
         <Organization>TIM S.p.A</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Filip Ceglik</Name>
         <Organization>Filip Ceglik</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Francesco Russo</Name>
         <Organization>TIM S.p.A</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>François Goichon</Name>
         <Organization>Google</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Funny Tech</Name>
         <Organization>Funny Tech</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Gaoning Pan of Zhejiang University &amp; Ant Security Light-Year Lab</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Gaurav Kumar</Name>
         <Organization>Gaurav Kumar</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Gourab Sadhukhan</Name>
         <Organization>Gourab Sadhukhan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Graham Rymer</Name>
         <Organization>University Information Services, University of Cambridge</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Hangfan Zhang</Name>
         <Organization>Hangfan Zhang</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Harsh Mukeshbhai Joshi</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Himanshu Phulwariya</Name>
         <Organization>Himanshu Phulwariya</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ioannis Charalambous</Name>
         <Organization>NCC Group</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ivo Palazzolo</Name>
         <Organization>Daimler TSS</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Bui Dinh Bao aka 0xd0ff9 of Zalo Security Team (VNG Corp)</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jacob Thompson</Name>
         <Organization>FireEye</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jakub Palaczynski</Name>
         <Organization>Jakub Palaczynski</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jakub Palaczynski</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jakub Plusczok</Name>
         <Organization>Jakub Plusczok</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Zouhair Janatil-Idrissi of Telecom Nancy</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jeffrey Martin</Name>
         <Organization>Rapid7</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Joe Almeida</Name>
         <Organization>Globlue Technologies</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Karthick Selvaraj</Name>
         <Organization>Karthick Selvaraj</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Kartik Sharma</Name>
         <Organization>Kartik Sharma</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Kaustubh Kale</Name>
         <Organization>Kaustubh Kale</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Khuyen Nguyen</Name>
         <Organization>secgit.com</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Kirtan Patel</Name>
         <Organization>Kirtan Patel</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Kritsada Sunthornwutthikrai</Name>
         <Organization>Secure D Center Cybersecurity Team</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Kunal Gambhir</Name>
         <Organization>Kunal Gambhir</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Kylinking</Name>
         <Organization>NSFocus Security Team</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ria from iZOOlogic</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Larry W. Cashdollar</Name>
         <Organization>Larry W. Cashdollar</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Le Xuan Tuyen - VNPT ISC working with Trend Micro Zero Day Initiative</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Long Nguyễn Hữu Vũ</Name>
         <Organization>Long Nguyễn Hữu Vũ</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Longofo</Name>
         <Organization>Knownsec 404 Team</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Luca Di Giuseppe</Name>
         <Organization>TIM S.p.A</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Magrabur Alam Sofily</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mansouri Badis</Name>
         <Organization>Mansouri Badis</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Markus Loewe</Name>
         <Organization>Markus Loewe</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Massimiliano Brolli</Name>
         <Organization>TIM S.p.A</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mateusz Dabrowski</Name>
         <Organization>Mateusz Dabrowski</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Matthew Harlow</Name>
         <Organization>EthicalHacker 20</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mayank Kumar</Name>
         <Organization>Mayank Kumar</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mayank Malik, Kartik Sharma</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Micah Van Deusen</Name>
         <Organization>Micah Van Deusen</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Olivier Chatelain</Name>
         <Organization>Olivier Chatelain</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Omkar Ghaisas</Name>
         <Organization>Omkar Ghaisas</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Osman Ahmed Hassan</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Pankaj Kumar Thakur from Nepal</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Philippe Antoine of Telecom Nancy</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Piotr Madej</Name>
         <Organization>ING Tech Poland</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sai Prashanth Pulisetti</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Pratish Bhansali</Name>
         <Organization>Pratish Bhansali</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Preeyakorn Keadsai</Name>
         <Organization>Secure D Center Cybersecurity Team</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Quynh Le of VNPT ISC working with Trend Micro Zero Day Initiative</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Riccardo Donini</Name>
         <Organization>Riccardo Donini</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Rick Verdoes &amp; Danny de Weille of HackDefense </Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ryan awsmhacks Preston</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Robert Lee Dick</Name>
         <Organization>Robert Lee Dick</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Roger Meyer</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ronak Nahar</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Rudi Andriano</Name>
         <Organization>Rudi Andriano</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Rui Zhong</Name>
         <Organization>Rui Zhong</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sameer Goyal</Name>
         <Organization>Sameer Goyal</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sergey Ostanin</Name>
         <Organization>Sergey Ostanin</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Shahid Ahmed</Name>
         <Organization>Shahid Ahmed</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Shahid Ahmed</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Shiva Gupta</Name>
         <Organization>Shiva Hacker One</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Shubham Maheshwari</Name>
         <Organization>Shubham Maheshwari</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sidney Omondi of Salaam Technology</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Soumajit Mukherjee</Name>
         <Organization>Soumajit Mukherjee</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sparsh Gupta</Name>
         <Organization>Sparsh Gupta</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Spyridon Chatzimichail of OTE Hellenic Telecommunications Organization S.A.</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Srikar V - exp1o1t9r</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Kryptos Logic - Threat Intelligence Platform</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sumit Sah</Name>
         <Organization>Sumit Sah</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Supun Madubashana Halangoda</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Suresh Nadar</Name>
         <Organization>Suresh Nadar</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Swapnil Maurya - "swapmaurya20"</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Thai Nguyen</Name>
         <Organization>ECQ</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Tomasz Stachowicz</Name>
         <Organization>Tomasz Stachowicz</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>thiscodecc</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Trung Le</Name>
         <Organization>Trung Le</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Tuan Anh Nguyen of Viettel Cyber Security working with Trend Micro Zero Day Initiative</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Tuan Anh Nguyen</Name>
         <Organization>Viettel Cyber Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Vaibhav Gaikwad</Name>
         <Organization>Knock Security Solutions</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ved Prabhu</Name>
         <Organization>Ved Prabhu</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Venkata Sateesh Netti (str4n63r)</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Viktor Gazdag</Name>
         <Organization>NCC Group</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Walid Faour</Name>
         <Organization>Walid Faour</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Walid Hossain</Name>
         <Organization>Walid Hossain</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Venustech ADLab</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Xingwei Lin</Name>
         <Organization>Ant Security Light-Year Lab</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Xinlei Ying</Name>
         <Organization>Ant Security Light-Year Lab</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Xu Yuanzhen of Alibaba Cloud Security Team</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Yaoguang Chen</Name>
         <Organization>Ant Security Light-Year Lab</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Yassine Triki</Name>
         <Organization>Yassine Triki</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Yatin Sharma</Name>
         <Organization>Yatin Sharma</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Yi Ren</Name>
         <Organization>Alibaba</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Yongheng Chen</Name>
         <Organization>Yongheng Chen</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Yu Wang</Name>
         <Organization>BMH Security Team</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Yuyue Wang</Name>
         <Organization>Alibaba</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Julien Zhan of Telecom Nancy</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Zhiqiang Zang of University of Texas at Austin</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>voidfyoo of Chaitin Security Research Lab</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>codeplutos</Name>
         <Organization>AntGroup FG Security Lab</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ai Ho (j3ssiejjj) </Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>r00t4dm from A-TEAM of Legendsec at Qi'anxin Group</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Siva Pathela</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Marwan Albahar</Name>
         <Organization></Organization>
      </Acknowledgment>
   </Acknowledgments>
   <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Name="Oracle" Type="Vendor">
         <Branch Name="Oracle Big Data Graph" Type="Product Family">
            <Branch Name="Big Data Spatial and Graph" Type="Product Name">
               <Branch Name="Prior to 2.4" Type="Product Version">
                  <FullProductName ProductID="P-11528V-Prior to 2.4">Big Data Spatial and Graph Version Prior to 2.4</FullProductName>
               </Branch>
               <Branch Name="Prior to 20.2" Type="Product Version">
                  <FullProductName ProductID="P-11528V-Prior to 20.2">Big Data Spatial and Graph Version Prior to 20.2</FullProductName>
               </Branch>
               <Branch Name="Prior to 3.0" Type="Product Version">
                  <FullProductName ProductID="P-11528V-Prior to 3.0">Big Data Spatial and Graph Version Prior to 3.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Communications" Type="Product Family">
            <Branch Name="Communications Services Gatekeeper" Type="Product Name">
               <Branch Name="7" Type="Product Version">
                  <FullProductName ProductID="P-5381V-7">Communications Services Gatekeeper Version 7</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Session Border Controller" Type="Product Name">
               <Branch Name="8.2-8.4" Type="Product Version">
                  <FullProductName ProductID="P-10750V-8.2-8.4">Communications Session Border Controller Version 8.2-8.4</FullProductName>
               </Branch>
               <Branch Name="8.3" Type="Product Version">
                  <FullProductName ProductID="P-10750V-8.3">Communications Session Border Controller Version 8.3</FullProductName>
               </Branch>
               <Branch Name="8.4" Type="Product Version">
                  <FullProductName ProductID="P-10750V-8.4">Communications Session Border Controller Version 8.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Enterprise Session Border Controller" Type="Product Name">
               <Branch Name="8.4" Type="Product Version">
                  <FullProductName ProductID="P-10757V-8.4">Enterprise Session Border Controller Version 8.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications EAGLE (Software)" Type="Product Name">
               <Branch Name="46.6.0-46.8.2" Type="Product Version">
                  <FullProductName ProductID="P-10768V-46.6.0-46.8.2">Communications EAGLE (Software) Version 46.6.0-46.8.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Application Session Controller" Type="Product Name">
               <Branch Name="3.8m0" Type="Product Version">
                  <FullProductName ProductID="P-10769V-3.8m0">Communications Application Session Controller Version 3.8m0</FullProductName>
               </Branch>
               <Branch Name="3.9m0p1" Type="Product Version">
                  <FullProductName ProductID="P-10769V-3.9m0p1">Communications Application Session Controller Version 3.9m0p1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Session Report Manager" Type="Product Name">
               <Branch Name="8.2.0-8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-10770V-8.2.0-8.2.2">Communications Session Report Manager Version 8.2.0-8.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Session Route Manager" Type="Product Name">
               <Branch Name="8.2.0-8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-10771V-8.2.0-8.2.2">Communications Session Route Manager Version 8.2.0-8.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications WebRTC Session Controller" Type="Product Name">
               <Branch Name="7.2" Type="Product Version">
                  <FullProductName ProductID="P-10811V-7.2">Communications WebRTC Session Controller Version 7.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Diameter Signaling Router (DSR)" Type="Product Name">
               <Branch Name="8.0.0.0-8.4.0.5" Type="Product Version">
                  <FullProductName ProductID="P-10899V-8.0.0.0-8.4.0.5">Communications Diameter Signaling Router (DSR) Version 8.0.0.0-8.4.0.5</FullProductName>
               </Branch>
               <Branch Name="IDIH: 8.0.0-8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-10899V-IDIH: 8.0.0-8.2.2">Communications Diameter Signaling Router (DSR) Version IDIH: 8.0.0-8.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Evolved Communications Application Server" Type="Product Name">
               <Branch Name="7.1" Type="Product Version">
                  <FullProductName ProductID="P-10994V-7.1">Communications Evolved Communications Application Server Version 7.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Element Manager" Type="Product Name">
               <Branch Name="8.2.0-8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-11052V-8.2.0-8.2.2">Communications Element Manager Version 8.2.0-8.2.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Communications Applications" Type="Product Family">
            <Branch Name="Communications Billing and Revenue Management" Type="Product Name">
               <Branch Name="12.0.0.2.0" Type="Product Version">
                  <FullProductName ProductID="P-2136V-12.0.0.2.0">Communications Billing and Revenue Management Version 12.0.0.2.0</FullProductName>
               </Branch>
               <Branch Name="12.0.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-2136V-12.0.0.3.0">Communications Billing and Revenue Management Version 12.0.0.3.0</FullProductName>
               </Branch>
               <Branch Name="7.5.0.23.0" Type="Product Version">
                  <FullProductName ProductID="P-2136V-7.5.0.23.0">Communications Billing and Revenue Management Version 7.5.0.23.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Offline Mediation Controller" Type="Product Name">
               <Branch Name="12.0.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-2269V-12.0.0.3.0">Communications Offline Mediation Controller Version 12.0.0.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Unified Inventory Management" Type="Product Name">
               <Branch Name="7.3.0" Type="Product Version">
                  <FullProductName ProductID="P-4516V-7.3.0">Communications Unified Inventory Management Version 7.3.0</FullProductName>
               </Branch>
               <Branch Name="7.4.0" Type="Product Version">
                  <FullProductName ProductID="P-4516V-7.4.0">Communications Unified Inventory Management Version 7.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Messaging Server" Type="Product Name">
               <Branch Name="8.1" Type="Product Version">
                  <FullProductName ProductID="P-8496V-8.1">Communications Messaging Server Version 8.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications BRM - Elastic Charging Engine" Type="Product Name">
               <Branch Name="11.3.0.9.0" Type="Product Version">
                  <FullProductName ProductID="P-9742V-11.3.0.9.0">Communications BRM - Elastic Charging Engine Version 11.3.0.9.0</FullProductName>
               </Branch>
               <Branch Name="12.0.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-9742V-12.0.0.3.0">Communications BRM - Elastic Charging Engine Version 12.0.0.3.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Construction and Engineering" Type="Product Family">
            <Branch Name="Primavera Unifier" Type="Product Name">
               <Branch Name="16.1" Type="Product Version">
                  <FullProductName ProductID="P-10354V-16.1">Primavera Unifier Version 16.1</FullProductName>
               </Branch>
               <Branch Name="16.2" Type="Product Version">
                  <FullProductName ProductID="P-10354V-16.2">Primavera Unifier Version 16.2</FullProductName>
               </Branch>
               <Branch Name="17.7-17.12" Type="Product Version">
                  <FullProductName ProductID="P-10354V-17.7-17.12">Primavera Unifier Version 17.7-17.12</FullProductName>
               </Branch>
               <Branch Name="18.8" Type="Product Version">
                  <FullProductName ProductID="P-10354V-18.8">Primavera Unifier Version 18.8</FullProductName>
               </Branch>
               <Branch Name="19.12" Type="Product Version">
                  <FullProductName ProductID="P-10354V-19.12">Primavera Unifier Version 19.12</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Instantis EnterpriseTrack" Type="Product Name">
               <Branch Name="17.1" Type="Product Version">
                  <FullProductName ProductID="P-10563V-17.1">Instantis EnterpriseTrack Version 17.1</FullProductName>
               </Branch>
               <Branch Name="17.2" Type="Product Version">
                  <FullProductName ProductID="P-10563V-17.2">Instantis EnterpriseTrack Version 17.2</FullProductName>
               </Branch>
               <Branch Name="17.3" Type="Product Version">
                  <FullProductName ProductID="P-10563V-17.3">Instantis EnterpriseTrack Version 17.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Primavera Gateway" Type="Product Name">
               <Branch Name="16.2.0-16.2.11" Type="Product Version">
                  <FullProductName ProductID="P-10605V-16.2.0-16.2.11">Primavera Gateway Version 16.2.0-16.2.11</FullProductName>
               </Branch>
               <Branch Name="17.12.0-17.12.8" Type="Product Version">
                  <FullProductName ProductID="P-10605V-17.12.0-17.12.8">Primavera Gateway Version 17.12.0-17.12.8</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Database Server" Type="Product Family">
            <Branch Name="Database - Enterprise Edition" Type="Product Name">
               <Branch Name="11.2.0.4" Type="Product Version">
                  <FullProductName ProductID="P-5V-11.2.0.4">Database - Enterprise Edition Version 11.2.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-5V-12.1.0.2">Database - Enterprise Edition Version 12.1.0.2</FullProductName>
               </Branch>
               <Branch Name="12.2.0.1" Type="Product Version">
                  <FullProductName ProductID="P-5V-12.2.0.1">Database - Enterprise Edition Version 12.2.0.1</FullProductName>
               </Branch>
               <Branch Name="18c" Type="Product Version">
                  <FullProductName ProductID="P-5V-18c">Database - Enterprise Edition Version 18c</FullProductName>
               </Branch>
               <Branch Name="19c" Type="Product Version">
                  <FullProductName ProductID="P-5V-19c">Database - Enterprise Edition Version 19c</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Text" Type="Product Name">
               <Branch Name="11.2.0.4" Type="Product Version">
                  <FullProductName ProductID="P-211V-11.2.0.4">Text Version 11.2.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-211V-12.1.0.2">Text Version 12.1.0.2</FullProductName>
               </Branch>
               <Branch Name="12.2.0.1" Type="Product Version">
                  <FullProductName ProductID="P-211V-12.2.0.1">Text Version 12.2.0.1</FullProductName>
               </Branch>
               <Branch Name="18c" Type="Product Version">
                  <FullProductName ProductID="P-211V-18c">Text Version 18c</FullProductName>
               </Branch>
               <Branch Name="19c" Type="Product Version">
                  <FullProductName ProductID="P-211V-19c">Text Version 19c</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Spatial and Graph" Type="Product Name">
               <Branch Name="11.2.0.4" Type="Product Version">
                  <FullProductName ProductID="P-619V-11.2.0.4">Spatial and Graph Version 11.2.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-619V-12.1.0.2">Spatial and Graph Version 12.1.0.2</FullProductName>
               </Branch>
               <Branch Name="12.2.0.1" Type="Product Version">
                  <FullProductName ProductID="P-619V-12.2.0.1">Spatial and Graph Version 12.2.0.1</FullProductName>
               </Branch>
               <Branch Name="18c" Type="Product Version">
                  <FullProductName ProductID="P-619V-18c">Spatial and Graph Version 18c</FullProductName>
               </Branch>
               <Branch Name="19c" Type="Product Version">
                  <FullProductName ProductID="P-619V-19c">Spatial and Graph Version 19c</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Application Express (APEX)" Type="Product Name">
               <Branch Name="Prior to 20.2" Type="Product Version">
                  <FullProductName ProductID="P-1348V-Prior to 20.2">Application Express (APEX) Version Prior to 20.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="SQL Developer" Type="Product Name">
               <Branch Name="11.2.0.4" Type="Product Version">
                  <FullProductName ProductID="P-1875V-11.2.0.4">SQL Developer Version 11.2.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-1875V-12.1.0.2">SQL Developer Version 12.1.0.2</FullProductName>
               </Branch>
               <Branch Name="12.2.0.1" Type="Product Version">
                  <FullProductName ProductID="P-1875V-12.2.0.1">SQL Developer Version 12.2.0.1</FullProductName>
               </Branch>
               <Branch Name="18c" Type="Product Version">
                  <FullProductName ProductID="P-1875V-18c">SQL Developer Version 18c</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle E-Business Suite" Type="Product Family">
            <Branch Name="Applications Manager" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-99V-12.1.3">Applications Manager Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3 - 12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-99V-12.2.3 - 12.2.10">Applications Manager Version 12.2.3 - 12.2.10</FullProductName>
               </Branch>
               <Branch Name="12.2.3 - 12.2.7" Type="Product Version">
                  <FullProductName ProductID="P-99V-12.2.3 - 12.2.7">Applications Manager Version 12.2.3 - 12.2.7</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Marketing" Type="Product Name">
               <Branch Name="12.1.1 - 12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.1.1 - 12.1.3">Marketing Version 12.1.1 - 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3 - 12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.2.3 - 12.2.10">Marketing Version 12.2.3 - 12.2.10</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Application Object Library" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-510V-12.1.3">Application Object Library Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3 - 12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-510V-12.2.3 - 12.2.10">Application Object Library Version 12.2.3 - 12.2.10</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Trade Management" Type="Product Name">
               <Branch Name="12.1.1 - 12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-765V-12.1.1 - 12.1.3">Trade Management Version 12.1.1 - 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-765V-12.1.3">Trade Management Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3 - 12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-765V-12.2.3 - 12.2.10">Trade Management Version 12.2.3 - 12.2.10</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Universal Work Queue" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-778V-12.1.3">Universal Work Queue Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3 - 12.2.9" Type="Product Version">
                  <FullProductName ProductID="P-778V-12.2.3 - 12.2.9">Universal Work Queue Version 12.2.3 - 12.2.9</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Installed Base" Type="Product Name">
               <Branch Name="12.1.1 - 12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1118V-12.1.1 - 12.1.3">Installed Base Version 12.1.1 - 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3 - 12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-1118V-12.2.3 - 12.2.10">Installed Base Version 12.2.3 - 12.2.10</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="CRM Technical Foundation" Type="Product Name">
               <Branch Name="12.1.1 - 12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1199V-12.1.1 - 12.1.3">CRM Technical Foundation Version 12.1.1 - 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1199V-12.1.3">CRM Technical Foundation Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3 - 12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-1199V-12.2.3 - 12.2.10">CRM Technical Foundation Version 12.2.3 - 12.2.10</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="One-to-One Fulfillment" Type="Product Name">
               <Branch Name="12.1.1 - 12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1379V-12.1.1 - 12.1.3">One-to-One Fulfillment Version 12.1.1 - 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1379V-12.1.3">One-to-One Fulfillment Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Applications Framework" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.1.3">Applications Framework Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3 - 12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.2.3 - 12.2.10">Applications Framework Version 12.2.3 - 12.2.10</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="E-Business Suite Secure Enterprise Search" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-4574V-12.1.3">E-Business Suite Secure Enterprise Search Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3 - 12.2.10" Type="Product Version">
                  <FullProductName ProductID="P-4574V-12.2.3 - 12.2.10">E-Business Suite Secure Enterprise Search Version 12.2.3 - 12.2.10</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Enterprise Manager" Type="Product Family">
            <Branch Name="Enterprise Manager Base Platform" Type="Product Name">
               <Branch Name="13.2.1.0" Type="Product Version">
                  <FullProductName ProductID="P-1370V-13.2.1.0">Enterprise Manager Base Platform Version 13.2.1.0</FullProductName>
               </Branch>
               <Branch Name="13.3.0.0" Type="Product Version">
                  <FullProductName ProductID="P-1370V-13.3.0.0">Enterprise Manager Base Platform Version 13.3.0.0</FullProductName>
               </Branch>
               <Branch Name="13.4.0.0" Type="Product Version">
                  <FullProductName ProductID="P-1370V-13.4.0.0">Enterprise Manager Base Platform Version 13.4.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Enterprise Manager for Peoplesoft" Type="Product Name">
               <Branch Name="13.4.1.1" Type="Product Version">
                  <FullProductName ProductID="P-2131V-13.4.1.1">Enterprise Manager for Peoplesoft Version 13.4.1.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Application Testing Suite" Type="Product Name">
               <Branch Name="13.3.0.1" Type="Product Version">
                  <FullProductName ProductID="P-4622V-13.3.0.1">Application Testing Suite Version 13.3.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="APM - Application Performance Management" Type="Product Name">
               <Branch Name="13.3.0.0" Type="Product Version">
                  <FullProductName ProductID="P-9572V-13.3.0.0">APM - Application Performance Management Version 13.3.0.0</FullProductName>
               </Branch>
               <Branch Name="13.4.0.0" Type="Product Version">
                  <FullProductName ProductID="P-9572V-13.4.0.0">APM - Application Performance Management Version 13.4.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Enterprise Manager Ops Center" Type="Product Name">
               <Branch Name="12.4.0.0" Type="Product Version">
                  <FullProductName ProductID="P-9835V-12.4.0.0">Enterprise Manager Ops Center Version 12.4.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Enterprise Manager for Storage Management" Type="Product Name">
               <Branch Name="13.3.0.0" Type="Product Version">
                  <FullProductName ProductID="P-10303V-13.3.0.0">Enterprise Manager for Storage Management Version 13.3.0.0</FullProductName>
               </Branch>
               <Branch Name="13.4.0.0" Type="Product Version">
                  <FullProductName ProductID="P-10303V-13.4.0.0">Enterprise Manager for Storage Management Version 13.4.0.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Financial Services Applications" Type="Product Family">
            <Branch Name="Financial Services Profitability Management" Type="Product Name">
               <Branch Name="8.0.6" Type="Product Version">
                  <FullProductName ProductID="P-5658V-8.0.6">Financial Services Profitability Management Version 8.0.6</FullProductName>
               </Branch>
               <Branch Name="8.0.7" Type="Product Version">
                  <FullProductName ProductID="P-5658V-8.0.7">Financial Services Profitability Management Version 8.0.7</FullProductName>
               </Branch>
               <Branch Name="8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5658V-8.1.0">Financial Services Profitability Management Version 8.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Funds Transfer Pricing" Type="Product Name">
               <Branch Name="8.0.6" Type="Product Version">
                  <FullProductName ProductID="P-5659V-8.0.6">Financial Services Funds Transfer Pricing Version 8.0.6</FullProductName>
               </Branch>
               <Branch Name="8.0.7" Type="Product Version">
                  <FullProductName ProductID="P-5659V-8.0.7">Financial Services Funds Transfer Pricing Version 8.0.7</FullProductName>
               </Branch>
               <Branch Name="8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5659V-8.1.0">Financial Services Funds Transfer Pricing Version 8.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Asset Liability Management" Type="Product Name">
               <Branch Name="8.0.6" Type="Product Version">
                  <FullProductName ProductID="P-5662V-8.0.6">Financial Services Asset Liability Management Version 8.0.6</FullProductName>
               </Branch>
               <Branch Name="8.0.7" Type="Product Version">
                  <FullProductName ProductID="P-5662V-8.0.7">Financial Services Asset Liability Management Version 8.0.7</FullProductName>
               </Branch>
               <Branch Name="8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5662V-8.1.0">Financial Services Asset Liability Management Version 8.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Balance Sheet Planning" Type="Product Name">
               <Branch Name="8.0.8" Type="Product Version">
                  <FullProductName ProductID="P-5663V-8.0.8">Financial Services Balance Sheet Planning Version 8.0.8</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Analytical Applications Infrastructure" Type="Product Name">
               <Branch Name="8.0.6-8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5680V-8.0.6-8.1.0">Financial Services Analytical Applications Infrastructure Version 8.0.6-8.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Analytical Applications Reconciliation Framework" Type="Product Name">
               <Branch Name="8.0.6-8.0.8" Type="Product Version">
                  <FullProductName ProductID="P-5748V-8.0.6-8.0.8">Financial Services Analytical Applications Reconciliation Framework Version 8.0.6-8.0.8</FullProductName>
               </Branch>
               <Branch Name="8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5748V-8.1.0">Financial Services Analytical Applications Reconciliation Framework Version 8.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Price Creation and Discovery" Type="Product Name">
               <Branch Name="8.0.6" Type="Product Version">
                  <FullProductName ProductID="P-5749V-8.0.6">Financial Services Price Creation and Discovery Version 8.0.6</FullProductName>
               </Branch>
               <Branch Name="8.0.7" Type="Product Version">
                  <FullProductName ProductID="P-5749V-8.0.7">Financial Services Price Creation and Discovery Version 8.0.7</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="FLEXCUBE Universal Banking" Type="Product Name">
               <Branch Name="12.3.0" Type="Product Version">
                  <FullProductName ProductID="P-9052V-12.3.0">FLEXCUBE Universal Banking Version 12.3.0</FullProductName>
               </Branch>
               <Branch Name="14.0.0-14.4.0" Type="Product Version">
                  <FullProductName ProductID="P-9052V-14.0.0-14.4.0">FLEXCUBE Universal Banking Version 14.0.0-14.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Liquidity Risk Management" Type="Product Name">
               <Branch Name="8.0.6" Type="Product Version">
                  <FullProductName ProductID="P-9096V-8.0.6">Financial Services Liquidity Risk Management Version 8.0.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="FLEXCUBE Core Banking" Type="Product Name">
               <Branch Name="11.5.0-11.7.0" Type="Product Version">
                  <FullProductName ProductID="P-9101V-11.5.0-11.7.0">FLEXCUBE Core Banking Version 11.5.0-11.7.0</FullProductName>
               </Branch>
               <Branch Name="5.2.0" Type="Product Version">
                  <FullProductName ProductID="P-9101V-5.2.0">FLEXCUBE Core Banking Version 5.2.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="FLEXCUBE Private Banking" Type="Product Name">
               <Branch Name="12.0.0" Type="Product Version">
                  <FullProductName ProductID="P-9110V-12.0.0">FLEXCUBE Private Banking Version 12.0.0</FullProductName>
               </Branch>
               <Branch Name="12.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9110V-12.1.0">FLEXCUBE Private Banking Version 12.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="FLEXCUBE Direct Banking" Type="Product Name">
               <Branch Name="12.0.1" Type="Product Version">
                  <FullProductName ProductID="P-9111V-12.0.1">FLEXCUBE Direct Banking Version 12.0.1</FullProductName>
               </Branch>
               <Branch Name="12.0.2" Type="Product Version">
                  <FullProductName ProductID="P-9111V-12.0.2">FLEXCUBE Direct Banking Version 12.0.2</FullProductName>
               </Branch>
               <Branch Name="12.0.3" Type="Product Version">
                  <FullProductName ProductID="P-9111V-12.0.3">FLEXCUBE Direct Banking Version 12.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Banking Platform" Type="Product Name">
               <Branch Name="2.4.0-2.10.0" Type="Product Version">
                  <FullProductName ProductID="P-9178V-2.4.0-2.10.0">Banking Platform Version 2.4.0-2.10.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Data Foundation" Type="Product Name">
               <Branch Name="8.0.6-8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9180V-8.0.6-8.1.0">Financial Services Data Foundation Version 8.0.6-8.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Hedge Management and IFRS Valuations" Type="Product Name">
               <Branch Name="8.0.6-8.0.8" Type="Product Version">
                  <FullProductName ProductID="P-9332V-8.0.6-8.0.8">Financial Services Hedge Management and IFRS Valuations Version 8.0.6-8.0.8</FullProductName>
               </Branch>
               <Branch Name="8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9332V-8.1.0">Financial Services Hedge Management and IFRS Valuations Version 8.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Basel Regulatory Capital Internal Ratings Based Approach" Type="Product Name">
               <Branch Name="8.0.6-8.0.8" Type="Product Version">
                  <FullProductName ProductID="P-9450V-8.0.6-8.0.8">Financial Services Basel Regulatory Capital Internal Ratings Based Approach Version 8.0.6-8.0.8</FullProductName>
               </Branch>
               <Branch Name="8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9450V-8.1.0">Financial Services Basel Regulatory Capital Internal Ratings Based Approach Version 8.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Loan Loss Forecasting and Provisioning" Type="Product Name">
               <Branch Name="8.0.6-8.0.8" Type="Product Version">
                  <FullProductName ProductID="P-9474V-8.0.6-8.0.8">Financial Services Loan Loss Forecasting and Provisioning Version 8.0.6-8.0.8</FullProductName>
               </Branch>
               <Branch Name="8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9474V-8.1.0">Financial Services Loan Loss Forecasting and Provisioning Version 8.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Basel Regulatory Capital Basic" Type="Product Name">
               <Branch Name="8.0.6-8.0.8" Type="Product Version">
                  <FullProductName ProductID="P-9612V-8.0.6-8.0.8">Financial Services Basel Regulatory Capital Basic Version 8.0.6-8.0.8</FullProductName>
               </Branch>
               <Branch Name="8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9612V-8.1.0">Financial Services Basel Regulatory Capital Basic Version 8.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Insurance Data Foundation" Type="Product Name">
               <Branch Name="8.0.6-8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9755V-8.0.6-8.1.0">Insurance Data Foundation Version 8.0.6-8.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Retail Customer Analytics" Type="Product Name">
               <Branch Name="8.0.6" Type="Product Version">
                  <FullProductName ProductID="P-10214V-8.0.6">Financial Services Retail Customer Analytics Version 8.0.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Institutional Performance Analytics" Type="Product Name">
               <Branch Name="8.0.6" Type="Product Version">
                  <FullProductName ProductID="P-10215V-8.0.6">Financial Services Institutional Performance Analytics Version 8.0.6</FullProductName>
               </Branch>
               <Branch Name="8.0.7" Type="Product Version">
                  <FullProductName ProductID="P-10215V-8.0.7">Financial Services Institutional Performance Analytics Version 8.0.7</FullProductName>
               </Branch>
               <Branch Name="8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-10215V-8.1.0">Financial Services Institutional Performance Analytics Version 8.1.0</FullProductName>
               </Branch>
               <Branch Name="8.7.0" Type="Product Version">
                  <FullProductName ProductID="P-10215V-8.7.0">Financial Services Institutional Performance Analytics Version 8.7.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Data Integration Hub" Type="Product Name">
               <Branch Name="8.0.6" Type="Product Version">
                  <FullProductName ProductID="P-11289V-8.0.6">Financial Services Data Integration Hub Version 8.0.6</FullProductName>
               </Branch>
               <Branch Name="8.0.7" Type="Product Version">
                  <FullProductName ProductID="P-11289V-8.0.7">Financial Services Data Integration Hub Version 8.0.7</FullProductName>
               </Branch>
               <Branch Name="8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-11289V-8.1.0">Financial Services Data Integration Hub Version 8.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Data Governance for US Regulatory Reporting" Type="Product Name">
               <Branch Name="8.0.6-8.0.9" Type="Product Version">
                  <FullProductName ProductID="P-11669V-8.0.6-8.0.9">Financial Services Data Governance for US Regulatory Reporting Version 8.0.6-8.0.9</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Banking Digital Experience" Type="Product Name">
               <Branch Name="18.1" Type="Product Version">
                  <FullProductName ProductID="P-12605V-18.1">Banking Digital Experience Version 18.1</FullProductName>
               </Branch>
               <Branch Name="18.2" Type="Product Version">
                  <FullProductName ProductID="P-12605V-18.2">Banking Digital Experience Version 18.2</FullProductName>
               </Branch>
               <Branch Name="18.3" Type="Product Version">
                  <FullProductName ProductID="P-12605V-18.3">Banking Digital Experience Version 18.3</FullProductName>
               </Branch>
               <Branch Name="19.1" Type="Product Version">
                  <FullProductName ProductID="P-12605V-19.1">Banking Digital Experience Version 19.1</FullProductName>
               </Branch>
               <Branch Name="19.2" Type="Product Version">
                  <FullProductName ProductID="P-12605V-19.2">Banking Digital Experience Version 19.2</FullProductName>
               </Branch>
               <Branch Name="20.1" Type="Product Version">
                  <FullProductName ProductID="P-12605V-20.1">Banking Digital Experience Version 20.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Banking Corporate Lending" Type="Product Name">
               <Branch Name="12.3.0" Type="Product Version">
                  <FullProductName ProductID="P-12989V-12.3.0">Banking Corporate Lending Version 12.3.0</FullProductName>
               </Branch>
               <Branch Name="14.0.0-14.4.0" Type="Product Version">
                  <FullProductName ProductID="P-12989V-14.0.0-14.4.0">Banking Corporate Lending Version 14.0.0-14.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Banking Payments" Type="Product Name">
               <Branch Name="14.1.0-14.4.0" Type="Product Version">
                  <FullProductName ProductID="P-13011V-14.1.0-14.4.0">Banking Payments Version 14.1.0-14.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Regulatory Reporting with AgileREPORTER" Type="Product Name">
               <Branch Name="8.0.9.2.0" Type="Product Version">
                  <FullProductName ProductID="P-13077V-8.0.9.2.0">Financial Services Regulatory Reporting with AgileREPORTER Version 8.0.9.2.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Regulatory Reporting for US Federal Reserve" Type="Product Name">
               <Branch Name="8.0.6-8.0.9" Type="Product Version">
                  <FullProductName ProductID="P-13080V-8.0.6-8.0.9">Financial Services Regulatory Reporting for US Federal Reserve Version 8.0.6-8.0.9</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Market Risk Measurement and Management" Type="Product Name">
               <Branch Name="8.0.6" Type="Product Version">
                  <FullProductName ProductID="P-13111V-8.0.6">Financial Services Market Risk Measurement and Management Version 8.0.6</FullProductName>
               </Branch>
               <Branch Name="8.0.8" Type="Product Version">
                  <FullProductName ProductID="P-13111V-8.0.8">Financial Services Market Risk Measurement and Management Version 8.0.8</FullProductName>
               </Branch>
               <Branch Name="8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-13111V-8.1.0">Financial Services Market Risk Measurement and Management Version 8.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Regulatory Reporting for European Banking Authority" Type="Product Name">
               <Branch Name="8.0.6-8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-13147V-8.0.6-8.1.0">Financial Services Regulatory Reporting for European Banking Authority Version 8.0.6-8.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Liquidity Risk Measurement and Management" Type="Product Name">
               <Branch Name="8.0.7" Type="Product Version">
                  <FullProductName ProductID="P-13797V-8.0.7">Financial Services Liquidity Risk Measurement and Management Version 8.0.7</FullProductName>
               </Branch>
               <Branch Name="8.0.8" Type="Product Version">
                  <FullProductName ProductID="P-13797V-8.0.8">Financial Services Liquidity Risk Measurement and Management Version 8.0.8</FullProductName>
               </Branch>
               <Branch Name="8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-13797V-8.1.0">Financial Services Liquidity Risk Measurement and Management Version 8.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Insurance Accounting Analyzer" Type="Product Name">
               <Branch Name="8.0.9" Type="Product Version">
                  <FullProductName ProductID="P-13809V-8.0.9">Insurance Accounting Analyzer Version 8.0.9</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Insurance Allocation Manager for Enterprise Profitability" Type="Product Name">
               <Branch Name="8.0.8" Type="Product Version">
                  <FullProductName ProductID="P-13946V-8.0.8">Insurance Allocation Manager for Enterprise Profitability Version 8.0.8</FullProductName>
               </Branch>
               <Branch Name="8.1.0" Type="Product Version">
                  <FullProductName ProductID="P-13946V-8.1.0">Insurance Allocation Manager for Enterprise Profitability Version 8.1.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Food and Beverage Applications" Type="Product Family">
            <Branch Name="Hospitality Simphony" Type="Product Name">
               <Branch Name="18.1" Type="Product Version">
                  <FullProductName ProductID="P-11594V-18.1">Hospitality Simphony Version 18.1</FullProductName>
               </Branch>
               <Branch Name="18.2" Type="Product Version">
                  <FullProductName ProductID="P-11594V-18.2">Hospitality Simphony Version 18.2</FullProductName>
               </Branch>
               <Branch Name="19.1.0-19.1.2" Type="Product Version">
                  <FullProductName ProductID="P-11594V-19.1.0-19.1.2">Hospitality Simphony Version 19.1.0-19.1.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Hospitality RES 3700" Type="Product Name">
               <Branch Name="5.7" Type="Product Version">
                  <FullProductName ProductID="P-11596V-5.7">Hospitality RES 3700 Version 5.7</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Hospitality Reporting and Analytics" Type="Product Name">
               <Branch Name="9.1.0" Type="Product Version">
                  <FullProductName ProductID="P-11599V-9.1.0">Hospitality Reporting and Analytics Version 9.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Hospitality Materials Control" Type="Product Name">
               <Branch Name="18.1" Type="Product Version">
                  <FullProductName ProductID="P-12573V-18.1">Hospitality Materials Control Version 18.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Fusion Middleware" Type="Product Family">
            <Branch Name="JDeveloper" Type="Product Name">
               <Branch Name="11.1.1.9.0" Type="Product Version">
                  <FullProductName ProductID="P-807V-11.1.1.9.0">JDeveloper Version 11.1.1.9.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-807V-12.2.1.3.0">JDeveloper Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-807V-12.2.1.4.0">JDeveloper Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="HTTP Server" Type="Product Name">
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1042V-12.2.1.3.0">HTTP Server Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-1042V-12.2.1.4.0">HTTP Server Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="BI Publisher (formerly XML Publisher)" Type="Product Name">
               <Branch Name="11.1.1.9.0" Type="Product Version">
                  <FullProductName ProductID="P-1479V-11.1.1.9.0">BI Publisher (formerly XML Publisher) Version 11.1.1.9.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1479V-12.2.1.3.0">BI Publisher (formerly XML Publisher) Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-1479V-12.2.1.4.0">BI Publisher (formerly XML Publisher) Version 12.2.1.4.0</FullProductName>
               </Branch>
               <Branch Name="5.5.0.0.0" Type="Product Version">
                  <FullProductName ProductID="P-1479V-5.5.0.0.0">BI Publisher (formerly XML Publisher) Version 5.5.0.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebCenter Portal" Type="Product Name">
               <Branch Name="11.1.1.9.0" Type="Product Version">
                  <FullProductName ProductID="P-1696V-11.1.1.9.0">WebCenter Portal Version 11.1.1.9.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1696V-12.2.1.3.0">WebCenter Portal Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-1696V-12.2.1.4.0">WebCenter Portal Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Identity Manager Connector" Type="Product Name">
               <Branch Name="9.0" Type="Product Version">
                  <FullProductName ProductID="P-1999V-9.0">Identity Manager Connector Version 9.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Business Intelligence Enterprise Edition" Type="Product Name">
               <Branch Name="11.1.1.9.0" Type="Product Version">
                  <FullProductName ProductID="P-2025V-11.1.1.9.0">Business Intelligence Enterprise Edition Version 11.1.1.9.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-2025V-12.2.1.3.0">Business Intelligence Enterprise Edition Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-2025V-12.2.1.4.0">Business Intelligence Enterprise Edition Version 12.2.1.4.0</FullProductName>
               </Branch>
               <Branch Name="5.5.0.0.0" Type="Product Version">
                  <FullProductName ProductID="P-2025V-5.5.0.0.0">Business Intelligence Enterprise Edition Version 5.5.0.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Data Integrator" Type="Product Name">
               <Branch Name="11.1.1.9.0" Type="Product Version">
                  <FullProductName ProductID="P-2196V-11.1.1.9.0">Data Integrator Version 11.1.1.9.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-2196V-12.2.1.3.0">Data Integrator Version 12.2.1.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Outside In Technology" Type="Product Name">
               <Branch Name="8.5.4" Type="Product Version">
                  <FullProductName ProductID="P-2276V-8.5.4">Outside In Technology Version 8.5.4</FullProductName>
               </Branch>
               <Branch Name="8.5.5" Type="Product Version">
                  <FullProductName ProductID="P-2276V-8.5.5">Outside In Technology Version 8.5.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebLogic Server" Type="Product Name">
               <Branch Name="10.3.6.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-10.3.6.0.0">WebLogic Server Version 10.3.6.0.0</FullProductName>
               </Branch>
               <Branch Name="12.1.3.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.1.3.0.0">WebLogic Server Version 12.1.3.0.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.2.1.3.0">WebLogic Server Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.2.1.4.0">WebLogic Server Version 12.2.1.4.0</FullProductName>
               </Branch>
               <Branch Name="14.1.1.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-14.1.1.0.0">WebLogic Server Version 14.1.1.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Business Process Management Suite" Type="Product Name">
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5325V-12.2.1.3.0">Business Process Management Suite Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-5325V-12.2.1.4.0">Business Process Management Suite Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Enterprise Repository" Type="Product Name">
               <Branch Name="11.1.1.7.0" Type="Product Version">
                  <FullProductName ProductID="P-5326V-11.1.1.7.0">Enterprise Repository Version 11.1.1.7.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Access Manager" Type="Product Name">
               <Branch Name="11.1.2.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5565V-11.1.2.3.0">Access Manager Version 11.1.2.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Management Pack for Oracle GoldenGate" Type="Product Name">
               <Branch Name="12.2.1.2.0" Type="Product Version">
                  <FullProductName ProductID="P-5759V-12.2.1.2.0">Management Pack for Oracle GoldenGate Version 12.2.1.2.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="GoldenGate Big Data and Application Adapters" Type="Product Name">
               <Branch Name="12.3.2.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5760V-12.3.2.1.0">GoldenGate Big Data and Application Adapters Version 12.3.2.1.0</FullProductName>
               </Branch>
               <Branch Name="19.1.0.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5760V-19.1.0.0.0">GoldenGate Big Data and Application Adapters Version 19.1.0.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Endeca Information Discovery Studio" Type="Product Name">
               <Branch Name="3.2.0" Type="Product Version">
                  <FullProductName ProductID="P-9634V-3.2.0">Endeca Information Discovery Studio Version 3.2.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Managed File Transfer" Type="Product Name">
               <Branch Name="12.2.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-10198V-12.2.1.3.0">Managed File Transfer Version 12.2.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.4.0" Type="Product Version">
                  <FullProductName ProductID="P-10198V-12.2.1.4.0">Managed File Transfer Version 12.2.1.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Endeca Information Discovery Integrator" Type="Product Name">
               <Branch Name="3.2.0" Type="Product Version">
                  <FullProductName ProductID="P-10561V-3.2.0">Endeca Information Discovery Integrator Version 3.2.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle GraalVM" Type="Product Family">
            <Branch Name="GraalVM Enterprise Edition" Type="Product Name">
               <Branch Name="19.3.3" Type="Product Version">
                  <FullProductName ProductID="P-13497V-19.3.3">GraalVM Enterprise Edition Version 19.3.3</FullProductName>
               </Branch>
               <Branch Name="20.2.0" Type="Product Version">
                  <FullProductName ProductID="P-13497V-20.2.0">GraalVM Enterprise Edition Version 20.2.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Health Sciences Applications" Type="Product Family">
            <Branch Name="Healthcare Data Repository" Type="Product Name">
               <Branch Name="7.0.1" Type="Product Version">
                  <FullProductName ProductID="P-9161V-7.0.1">Healthcare Data Repository Version 7.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Health Sciences Empirica Signal" Type="Product Name">
               <Branch Name="9.0" Type="Product Version">
                  <FullProductName ProductID="P-9646V-9.0">Health Sciences Empirica Signal Version 9.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Healthcare Foundation" Type="Product Name">
               <Branch Name="7.1.1" Type="Product Version">
                  <FullProductName ProductID="P-12950V-7.1.1">Healthcare Foundation Version 7.1.1</FullProductName>
               </Branch>
               <Branch Name="7.2.0" Type="Product Version">
                  <FullProductName ProductID="P-12950V-7.2.0">Healthcare Foundation Version 7.2.0</FullProductName>
               </Branch>
               <Branch Name="7.2.1" Type="Product Version">
                  <FullProductName ProductID="P-12950V-7.2.1">Healthcare Foundation Version 7.2.1</FullProductName>
               </Branch>
               <Branch Name="7.3.0" Type="Product Version">
                  <FullProductName ProductID="P-12950V-7.3.0">Healthcare Foundation Version 7.3.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Hospitality Applications" Type="Product Family">
            <Branch Name="Hospitality OPERA 5 Property Services" Type="Product Name">
               <Branch Name="5.5" Type="Product Version">
                  <FullProductName ProductID="P-11580V-5.5">Hospitality OPERA 5 Property Services Version 5.5</FullProductName>
               </Branch>
               <Branch Name="5.6" Type="Product Version">
                  <FullProductName ProductID="P-11580V-5.6">Hospitality OPERA 5 Property Services Version 5.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Hospitality Guest Access" Type="Product Name">
               <Branch Name="4.2.0" Type="Product Version">
                  <FullProductName ProductID="P-12617V-4.2.0">Hospitality Guest Access Version 4.2.0</FullProductName>
               </Branch>
               <Branch Name="4.2.1" Type="Product Version">
                  <FullProductName ProductID="P-12617V-4.2.1">Hospitality Guest Access Version 4.2.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Hospitality Suite8" Type="Product Name">
               <Branch Name="8.10.2" Type="Product Version">
                  <FullProductName ProductID="P-12619V-8.10.2">Hospitality Suite8 Version 8.10.2</FullProductName>
               </Branch>
               <Branch Name="8.11-8.14" Type="Product Version">
                  <FullProductName ProductID="P-12619V-8.11-8.14">Hospitality Suite8 Version 8.11-8.14</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Hyperion" Type="Product Family">
            <Branch Name="Hyperion Analytic Provider Services" Type="Product Name">
               <Branch Name="11.1.2.4" Type="Product Version">
                  <FullProductName ProductID="P-4349V-11.1.2.4">Hyperion Analytic Provider Services Version 11.1.2.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Hyperion BI+" Type="Product Name">
               <Branch Name="11.1.2.4" Type="Product Version">
                  <FullProductName ProductID="P-4361V-11.1.2.4">Hyperion BI+ Version 11.1.2.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Hyperion Essbase" Type="Product Name">
               <Branch Name="11.1.2.4" Type="Product Version">
                  <FullProductName ProductID="P-4379V-11.1.2.4">Hyperion Essbase Version 11.1.2.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Hyperion Infrastructure Technology" Type="Product Name">
               <Branch Name="11.1.2.4" Type="Product Version">
                  <FullProductName ProductID="P-4392V-11.1.2.4">Hyperion Infrastructure Technology Version 11.1.2.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Hyperion Planning" Type="Product Name">
               <Branch Name="11.1.2.4" Type="Product Version">
                  <FullProductName ProductID="P-4402V-11.1.2.4">Hyperion Planning Version 11.1.2.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Hyperion Lifecycle Management" Type="Product Name">
               <Branch Name="11.1.2.4" Type="Product Version">
                  <FullProductName ProductID="P-4482V-11.1.2.4">Hyperion Lifecycle Management Version 11.1.2.4</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Insurance Applications" Type="Product Family">
            <Branch Name="Insurance Policy Administration J2EE" Type="Product Name">
               <Branch Name="10.2.0.37" Type="Product Version">
                  <FullProductName ProductID="P-5279V-10.2.0.37">Insurance Policy Administration J2EE Version 10.2.0.37</FullProductName>
               </Branch>
               <Branch Name="10.2.4.12" Type="Product Version">
                  <FullProductName ProductID="P-5279V-10.2.4.12">Insurance Policy Administration J2EE Version 10.2.4.12</FullProductName>
               </Branch>
               <Branch Name="11.0.2.25" Type="Product Version">
                  <FullProductName ProductID="P-5279V-11.0.2.25">Insurance Policy Administration J2EE Version 11.0.2.25</FullProductName>
               </Branch>
               <Branch Name="11.1.0.15" Type="Product Version">
                  <FullProductName ProductID="P-5279V-11.1.0.15">Insurance Policy Administration J2EE Version 11.1.0.15</FullProductName>
               </Branch>
               <Branch Name="11.2.0.26" Type="Product Version">
                  <FullProductName ProductID="P-5279V-11.2.0.26">Insurance Policy Administration J2EE Version 11.2.0.26</FullProductName>
               </Branch>
               <Branch Name="11.2.2.0" Type="Product Version">
                  <FullProductName ProductID="P-5279V-11.2.2.0">Insurance Policy Administration J2EE Version 11.2.2.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Insurance Rules Palette" Type="Product Name">
               <Branch Name="10.2.0.37" Type="Product Version">
                  <FullProductName ProductID="P-5288V-10.2.0.37">Insurance Rules Palette Version 10.2.0.37</FullProductName>
               </Branch>
               <Branch Name="10.2.4.12" Type="Product Version">
                  <FullProductName ProductID="P-5288V-10.2.4.12">Insurance Rules Palette Version 10.2.4.12</FullProductName>
               </Branch>
               <Branch Name="11.0.2.25" Type="Product Version">
                  <FullProductName ProductID="P-5288V-11.0.2.25">Insurance Rules Palette Version 11.0.2.25</FullProductName>
               </Branch>
               <Branch Name="11.1.0.15" Type="Product Version">
                  <FullProductName ProductID="P-5288V-11.1.0.15">Insurance Rules Palette Version 11.1.0.15</FullProductName>
               </Branch>
               <Branch Name="11.2.0.26" Type="Product Version">
                  <FullProductName ProductID="P-5288V-11.2.0.26">Insurance Rules Palette Version 11.2.0.26</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Insurance Insbridge Rating and Underwriting" Type="Product Name">
               <Branch Name="5.0.0.0 - 5.6.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5484V-5.0.0.0 - 5.6.0.0">Insurance Insbridge Rating and Underwriting Version 5.0.0.0 - 5.6.0.0</FullProductName>
               </Branch>
               <Branch Name="5.6.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5484V-5.6.1.0">Insurance Insbridge Rating and Underwriting Version 5.6.1.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Java SE" Type="Product Family">
            <Branch Name="Java SE JDK and JRE" Type="Product Name">
               <Branch Name="11.0.8" Type="Product Version">
                  <FullProductName ProductID="P-856V-11.0.8">Java SE JDK and JRE Version 11.0.8</FullProductName>
               </Branch>
               <Branch Name="15" Type="Product Version">
                  <FullProductName ProductID="P-856V-15">Java SE JDK and JRE Version 15</FullProductName>
               </Branch>
               <Branch Name="15; Java SE Embedded: 8u261" Type="Product Version">
                  <FullProductName ProductID="P-856V-15; Java SE Embedded: 8u261">Java SE JDK and JRE Version 15; Java SE Embedded: 8u261</FullProductName>
               </Branch>
               <Branch Name="8u261" Type="Product Version">
                  <FullProductName ProductID="P-856V-8u261">Java SE JDK and JRE Version 8u261</FullProductName>
               </Branch>
               <Branch Name="Java SE: 11.0.8" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE: 11.0.8">Java SE JDK and JRE Version Java SE: 11.0.8</FullProductName>
               </Branch>
               <Branch Name="Java SE: 7u271" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE: 7u271">Java SE JDK and JRE Version Java SE: 7u271</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle MySQL" Type="Product Family">
            <Branch Name="MySQL Workbench" Type="Product Name">
               <Branch Name="8.0.21 and prior" Type="Product Version">
                  <FullProductName ProductID="P-4627V-8.0.21 and prior">MySQL Workbench Version 8.0.21 and prior</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MySQL Server" Type="Product Name">
               <Branch Name="5.6.49 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.6.49 and prior">MySQL Server Version 5.6.49 and prior</FullProductName>
               </Branch>
               <Branch Name="5.7.31 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.7.31 and prior">MySQL Server Version 5.7.31 and prior</FullProductName>
               </Branch>
               <Branch Name="8.0.20 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8478V-8.0.20 and prior">MySQL Server Version 8.0.20 and prior</FullProductName>
               </Branch>
               <Branch Name="8.0.21 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8478V-8.0.21 and prior">MySQL Server Version 8.0.21 and prior</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MySQL Cluster" Type="Product Name">
               <Branch Name="7.3.30 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8479V-7.3.30 and prior">MySQL Cluster Version 7.3.30 and prior</FullProductName>
               </Branch>
               <Branch Name="7.4.29 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8479V-7.4.29 and prior">MySQL Cluster Version 7.4.29 and prior</FullProductName>
               </Branch>
               <Branch Name="7.5.19 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8479V-7.5.19 and prior">MySQL Cluster Version 7.5.19 and prior</FullProductName>
               </Branch>
               <Branch Name="7.6.15 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8479V-7.6.15 and prior">MySQL Cluster Version 7.6.15 and prior</FullProductName>
               </Branch>
               <Branch Name="8.0.21 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8479V-8.0.21 and prior">MySQL Cluster Version 8.0.21 and prior</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MySQL Enterprise Monitor" Type="Product Name">
               <Branch Name="8.0.21 and prior" Type="Product Version">
                  <FullProductName ProductID="P-8480V-8.0.21 and prior">MySQL Enterprise Monitor Version 8.0.21 and prior</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle PeopleSoft" Type="Product Family">
            <Branch Name="PeopleSoft Enterprise HCM Global Payroll Core" Type="Product Name">
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-5055V-9.2">PeopleSoft Enterprise HCM Global Payroll Core Version 9.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise PT PeopleTools" Type="Product Name">
               <Branch Name="8.56" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.56">PeopleSoft Enterprise PT PeopleTools Version 8.56</FullProductName>
               </Branch>
               <Branch Name="8.57" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.57">PeopleSoft Enterprise PT PeopleTools Version 8.57</FullProductName>
               </Branch>
               <Branch Name="8.58" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.58">PeopleSoft Enterprise PT PeopleTools Version 8.58</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise SCM eSupplier Connection" Type="Product Name">
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-5122V-9.2">PeopleSoft Enterprise SCM eSupplier Connection Version 9.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Policy Automation" Type="Product Family">
            <Branch Name="Policy Automation" Type="Product Name">
               <Branch Name="12.2.0 - 12.2.20" Type="Product Version">
                  <FullProductName ProductID="P-5624V-12.2.0 - 12.2.20">Policy Automation Version 12.2.0 - 12.2.20</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Policy Automation for Mobile Devices" Type="Product Name">
               <Branch Name="12.2.0 - 12.2.20" Type="Product Version">
                  <FullProductName ProductID="P-5626V-12.2.0 - 12.2.20">Policy Automation for Mobile Devices Version 12.2.0 - 12.2.20</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Policy Automation Connector for Siebel" Type="Product Name">
               <Branch Name="10.4.6" Type="Product Version">
                  <FullProductName ProductID="P-5627V-10.4.6">Policy Automation Connector for Siebel Version 10.4.6</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle REST Data Services" Type="Product Family">
            <Branch Name="REST Data Services" Type="Product Name">
               <Branch Name="11.2.0.4" Type="Product Version">
                  <FullProductName ProductID="P-9456V-11.2.0.4">REST Data Services Version 11.2.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-9456V-12.1.0.2">REST Data Services Version 12.1.0.2</FullProductName>
               </Branch>
               <Branch Name="12.2.0.1" Type="Product Version">
                  <FullProductName ProductID="P-9456V-12.2.0.1">REST Data Services Version 12.2.0.1</FullProductName>
               </Branch>
               <Branch Name="18c" Type="Product Version">
                  <FullProductName ProductID="P-9456V-18c">REST Data Services Version 18c</FullProductName>
               </Branch>
               <Branch Name="19c" Type="Product Version">
                  <FullProductName ProductID="P-9456V-19c">REST Data Services Version 19c</FullProductName>
               </Branch>
               <Branch Name="19c; Standalone ORDS: prior to 20.2.1" Type="Product Version">
                  <FullProductName ProductID="P-9456V-19c; Standalone ORDS: prior to 20.2.1">REST Data Services Version 19c; Standalone ORDS: prior to 20.2.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Retail Applications" Type="Product Family">
            <Branch Name="Retail Advanced Inventory Planning" Type="Product Name">
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-1785V-14.1">Retail Advanced Inventory Planning Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Assortment Planning" Type="Product Name">
               <Branch Name="15.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1788V-15.0.3.0">Retail Assortment Planning Version 15.0.3.0</FullProductName>
               </Branch>
               <Branch Name="16.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1788V-16.0.3.0">Retail Assortment Planning Version 16.0.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Integration Bus" Type="Product Name">
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-1807V-14.1">Retail Integration Bus Version 14.1</FullProductName>
               </Branch>
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-1807V-15.0">Retail Integration Bus Version 15.0</FullProductName>
               </Branch>
               <Branch Name="16.0" Type="Product Version">
                  <FullProductName ProductID="P-1807V-16.0">Retail Integration Bus Version 16.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Predictive Application Server" Type="Product Name">
               <Branch Name="14.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1823V-14.1.3.0">Retail Predictive Application Server Version 14.1.3.0</FullProductName>
               </Branch>
               <Branch Name="15.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1823V-15.0.3.0">Retail Predictive Application Server Version 15.0.3.0</FullProductName>
               </Branch>
               <Branch Name="16.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1823V-16.0.3.0">Retail Predictive Application Server Version 16.0.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Price Management" Type="Product Name">
               <Branch Name="14.0.4" Type="Product Version">
                  <FullProductName ProductID="P-1824V-14.0.4">Retail Price Management Version 14.0.4</FullProductName>
               </Branch>
               <Branch Name="14.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1824V-14.1.3.0">Retail Price Management Version 14.1.3.0</FullProductName>
               </Branch>
               <Branch Name="15.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1824V-15.0.3.0">Retail Price Management Version 15.0.3.0</FullProductName>
               </Branch>
               <Branch Name="16.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1824V-16.0.3.0">Retail Price Management Version 16.0.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Back Office" Type="Product Name">
               <Branch Name="14.0" Type="Product Version">
                  <FullProductName ProductID="P-2013V-14.0">Retail Back Office Version 14.0</FullProductName>
               </Branch>
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-2013V-14.1">Retail Back Office Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Central Office" Type="Product Name">
               <Branch Name="14.0" Type="Product Version">
                  <FullProductName ProductID="P-2016V-14.0">Retail Central Office Version 14.0</FullProductName>
               </Branch>
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-2016V-14.1">Retail Central Office Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Point-of-Service" Type="Product Name">
               <Branch Name="14.0" Type="Product Version">
                  <FullProductName ProductID="P-2017V-14.0">Retail Point-of-Service Version 14.0</FullProductName>
               </Branch>
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-2017V-14.1">Retail Point-of-Service Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Returns Management" Type="Product Name">
               <Branch Name="14.0" Type="Product Version">
                  <FullProductName ProductID="P-2020V-14.0">Retail Returns Management Version 14.0</FullProductName>
               </Branch>
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-2020V-14.1">Retail Returns Management Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Service Backbone" Type="Product Name">
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-10867V-14.1">Retail Service Backbone Version 14.1</FullProductName>
               </Branch>
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-10867V-15.0">Retail Service Backbone Version 15.0</FullProductName>
               </Branch>
               <Branch Name="16.0" Type="Product Version">
                  <FullProductName ProductID="P-10867V-16.0">Retail Service Backbone Version 16.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Xstore Point of Service" Type="Product Name">
               <Branch Name="15.0.3" Type="Product Version">
                  <FullProductName ProductID="P-11513V-15.0.3">Retail Xstore Point of Service Version 15.0.3</FullProductName>
               </Branch>
               <Branch Name="16.0.5" Type="Product Version">
                  <FullProductName ProductID="P-11513V-16.0.5">Retail Xstore Point of Service Version 16.0.5</FullProductName>
               </Branch>
               <Branch Name="17.0.3" Type="Product Version">
                  <FullProductName ProductID="P-11513V-17.0.3">Retail Xstore Point of Service Version 17.0.3</FullProductName>
               </Branch>
               <Branch Name="18.0.2" Type="Product Version">
                  <FullProductName ProductID="P-11513V-18.0.2">Retail Xstore Point of Service Version 18.0.2</FullProductName>
               </Branch>
               <Branch Name="19.0.1" Type="Product Version">
                  <FullProductName ProductID="P-11513V-19.0.1">Retail Xstore Point of Service Version 19.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Order Broker Cloud Service" Type="Product Name">
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-11520V-15.0">Retail Order Broker Cloud Service Version 15.0</FullProductName>
               </Branch>
               <Branch Name="16.0" Type="Product Version">
                  <FullProductName ProductID="P-11520V-16.0">Retail Order Broker Cloud Service Version 16.0</FullProductName>
               </Branch>
               <Branch Name="18.0" Type="Product Version">
                  <FullProductName ProductID="P-11520V-18.0">Retail Order Broker Cloud Service Version 18.0</FullProductName>
               </Branch>
               <Branch Name="19.0" Type="Product Version">
                  <FullProductName ProductID="P-11520V-19.0">Retail Order Broker Cloud Service Version 19.0</FullProductName>
               </Branch>
               <Branch Name="19.1" Type="Product Version">
                  <FullProductName ProductID="P-11520V-19.1">Retail Order Broker Cloud Service Version 19.1</FullProductName>
               </Branch>
               <Branch Name="19.2" Type="Product Version">
                  <FullProductName ProductID="P-11520V-19.2">Retail Order Broker Cloud Service Version 19.2</FullProductName>
               </Branch>
               <Branch Name="19.3" Type="Product Version">
                  <FullProductName ProductID="P-11520V-19.3">Retail Order Broker Cloud Service Version 19.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Bulk Data Integration" Type="Product Name">
               <Branch Name="15.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-12968V-15.0.3.0">Retail Bulk Data Integration Version 15.0.3.0</FullProductName>
               </Branch>
               <Branch Name="16.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-12968V-16.0.3.0">Retail Bulk Data Integration Version 16.0.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Customer Management and Segmentation Foundation" Type="Product Name">
               <Branch Name="18.0" Type="Product Version">
                  <FullProductName ProductID="P-13388V-18.0">Retail Customer Management and Segmentation Foundation Version 18.0</FullProductName>
               </Branch>
               <Branch Name="19.0" Type="Product Version">
                  <FullProductName ProductID="P-13388V-19.0">Retail Customer Management and Segmentation Foundation Version 19.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Siebel CRM" Type="Product Family">
            <Branch Name="Siebel Apps - Marketing" Type="Product Name">
               <Branch Name="20.7" Type="Product Version">
                  <FullProductName ProductID="P-8974V-20.7">Siebel Apps - Marketing Version 20.7</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel UI Framework" Type="Product Name">
               <Branch Name="20.8" Type="Product Version">
                  <FullProductName ProductID="P-9011V-20.8">Siebel UI Framework Version 20.8</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Supply Chain" Type="Product Family">
            <Branch Name="Transportation Management" Type="Product Name">
               <Branch Name="6.3.7" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.7">Transportation Management Version 6.3.7</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Agile Product Supplier Collaboration for Process" Type="Product Name">
               <Branch Name="6.2.0.0" Type="Product Version">
                  <FullProductName ProductID="P-4447V-6.2.0.0">Agile Product Supplier Collaboration for Process Version 6.2.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Agile PLM Framework" Type="Product Name">
               <Branch Name="9.3.3" Type="Product Version">
                  <FullProductName ProductID="P-4461V-9.3.3">Agile PLM Framework Version 9.3.3</FullProductName>
               </Branch>
               <Branch Name="9.3.5" Type="Product Version">
                  <FullProductName ProductID="P-4461V-9.3.5">Agile PLM Framework Version 9.3.5</FullProductName>
               </Branch>
               <Branch Name="9.3.6" Type="Product Version">
                  <FullProductName ProductID="P-4461V-9.3.6">Agile PLM Framework Version 9.3.6</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Systems" Type="Product Family">
            <Branch Name="Solaris Operating System" Type="Product Name">
               <Branch Name="10" Type="Product Version">
                  <FullProductName ProductID="P-10006V-10">Solaris Operating System Version 10</FullProductName>
               </Branch>
               <Branch Name="11" Type="Product Version">
                  <FullProductName ProductID="P-10006V-11">Solaris Operating System Version 11</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Sun ZFS Storage Appliance Kit (AK) Software" Type="Product Name">
               <Branch Name="8.8" Type="Product Version">
                  <FullProductName ProductID="P-10026V-8.8">Sun ZFS Storage Appliance Kit (AK) Software Version 8.8</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Fujitsu SPARC Servers Firmware" Type="Product Name">
               <Branch Name="Prior to XCP2362" Type="Product Version">
                  <FullProductName ProductID="P-10656V-Prior to XCP2362">Fujitsu SPARC Servers Firmware Version Prior to XCP2362</FullProductName>
               </Branch>
               <Branch Name="Prior to XCP3090" Type="Product Version">
                  <FullProductName ProductID="P-10656V-Prior to XCP3090">Fujitsu SPARC Servers Firmware Version Prior to XCP3090</FullProductName>
               </Branch>
               <Branch Name="prior to XCP3090" Type="Product Version">
                  <FullProductName ProductID="P-10656V-prior to XCP3090">Fujitsu SPARC Servers Firmware Version prior to XCP3090</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle TimesTen In-Memory Database" Type="Product Family">
            <Branch Name="TimesTen In-Memory Database" Type="Product Name">
               <Branch Name="Prior to 11.2.2.8.49" Type="Product Version">
                  <FullProductName ProductID="P-1870V-Prior to 11.2.2.8.49">TimesTen In-Memory Database Version Prior to 11.2.2.8.49</FullProductName>
               </Branch>
               <Branch Name="Prior to 18.1.3.1.0" Type="Product Version">
                  <FullProductName ProductID="P-1870V-Prior to 18.1.3.1.0">TimesTen In-Memory Database Version Prior to 18.1.3.1.0</FullProductName>
               </Branch>
               <Branch Name="Prior to 18.1.4.1.0" Type="Product Version">
                  <FullProductName ProductID="P-1870V-Prior to 18.1.4.1.0">TimesTen In-Memory Database Version Prior to 18.1.4.1.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Utilities Applications" Type="Product Family">
            <Branch Name="Utilities Framework" Type="Product Name">
               <Branch Name="2.2.0.0.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-2.2.0.0.0">Utilities Framework Version 2.2.0.0.0</FullProductName>
               </Branch>
               <Branch Name="4.2.0.2.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.2.0.2.0">Utilities Framework Version 4.2.0.2.0</FullProductName>
               </Branch>
               <Branch Name="4.2.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.2.0.3.0">Utilities Framework Version 4.2.0.3.0</FullProductName>
               </Branch>
               <Branch Name="4.3.0.1.0 - 4.3.0.6.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.3.0.1.0 - 4.3.0.6.0">Utilities Framework Version 4.3.0.1.0 - 4.3.0.6.0</FullProductName>
               </Branch>
               <Branch Name="4.4.0.0.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.4.0.0.0">Utilities Framework Version 4.4.0.0.0</FullProductName>
               </Branch>
               <Branch Name="4.4.0.2.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.4.0.2.0">Utilities Framework Version 4.4.0.2.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Virtualization" Type="Product Family">
            <Branch Name="VM VirtualBox" Type="Product Name">
               <Branch Name="Prior to 6.1.16" Type="Product Version">
                  <FullProductName ProductID="P-8370V-Prior to 6.1.16">VM VirtualBox Version Prior to 6.1.16</FullProductName>
               </Branch>
            </Branch>
         </Branch>
      </Branch>
   </ProductTree>
   <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-1832</Title>
      <Notes>
         <Note Audience="All" Ordinal="1" Title="Details" Type="Details">Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (Apache Derby)).  Supported versions that are affected are 16.1, 16.2, 17.7-17.12, 18.8 and  19.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Primavera Unifier accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Primavera Unifier. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-1832</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10354V-16.1</ProductID>
            <ProductID>P-10354V-16.2</ProductID>
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10354V-16.1</ProductID>
            <ProductID>P-10354V-16.2</ProductID>
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-9251</Title>
      <Notes>
         <Note Audience="All" Ordinal="2" Title="Details" Type="Details">Security-in-Depth issue in the Big Data Spatial and Graph product of Oracle Big Data Graph (component: Property Graph Analytics (jQuery)).   The supported version that is affected is Prior to 2.4. This vulnerability cannot be exploited in the context of this product. Note: CVEs addressed by this patch are not exploitable in the context of Property Graph and Analytics in Big Data Spatial and Graph product, thus the CVSS score is 0.0. CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-9251</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11528V-Prior to 2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11528V-Prior to 2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-1000031</Title>
      <Notes>
         <Note Audience="All" Ordinal="3" Title="Details" Type="Details">Vulnerability in the Oracle REST Data Services product of Oracle REST Data Services (component: General (Apache Commons FileUpload)).  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and  18c. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle REST Data Services.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle REST Data Services. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-1000031</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9456V-11.2.0.4</ProductID>
            <ProductID>P-9456V-12.1.0.2</ProductID>
            <ProductID>P-9456V-12.2.0.1</ProductID>
            <ProductID>P-9456V-18c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.0</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9456V-11.2.0.4</ProductID>
            <ProductID>P-9456V-12.1.0.2</ProductID>
            <ProductID>P-9456V-12.2.0.1</ProductID>
            <ProductID>P-9456V-18c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-1000031</Title>
      <Notes>
         <Note Audience="All" Ordinal="4" Title="Details" Type="Details">Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Mktg/Email Mktg Stand-Alone  (Apache Commons File Upload)).   The supported version that is affected is 20.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing.  Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-1000031</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8974V-20.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8974V-20.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-2510</Title>
      <Notes>
         <Note Audience="All" Ordinal="5" Title="Details" Type="Details">Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Jave APIs (BeanShell)).  Supported versions that are affected are 11.1.1.9.0 and  12.2.1.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-2510</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2196V-11.1.1.9.0</ProductID>
            <ProductID>P-2196V-12.2.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2196V-11.1.1.9.0</ProductID>
            <ProductID>P-2196V-12.2.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5725</Title>
      <Notes>
         <Note Audience="All" Ordinal="6" Title="Details" Type="Details">Security-in-Depth issue in the SQL Developer (JCraft JSch) component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and  18c. This vulnerability cannot be exploited in the context of this product.CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5725</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1875V-11.2.0.4</ProductID>
            <ProductID>P-1875V-12.1.0.2</ProductID>
            <ProductID>P-1875V-12.2.0.1</ProductID>
            <ProductID>P-1875V-18c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1875V-11.2.0.4</ProductID>
            <ProductID>P-1875V-12.1.0.2</ProductID>
            <ProductID>P-1875V-12.2.0.1</ProductID>
            <ProductID>P-1875V-18c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-12626</Title>
      <Notes>
         <Note Audience="All" Ordinal="7" Title="Details" Type="Details">Security-in-Depth issue in the SQL Developer (Apache POI) component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and  18c. This vulnerability cannot be exploited in the context of this product.CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-12626</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1875V-11.2.0.4</ProductID>
            <ProductID>P-1875V-12.1.0.2</ProductID>
            <ProductID>P-1875V-12.2.0.1</ProductID>
            <ProductID>P-1875V-18c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1875V-11.2.0.4</ProductID>
            <ProductID>P-1875V-12.1.0.2</ProductID>
            <ProductID>P-1875V-12.2.0.1</ProductID>
            <ProductID>P-1875V-18c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5645</Title>
      <Notes>
         <Note Audience="All" Ordinal="8" Title="Details" Type="Details">Security-in-Depth issue in the Big Data Spatial and Graph product of Oracle Big Data Graph (component: Property Graph Analytics (Apache Log4j)).   The supported version that is affected is Prior to 3.0. This vulnerability cannot be exploited in the context of this product. Note: CVEs addressed by this patch are not exploitable in the context of Property Graph and Analytics in Big Data Spatial and Graph product, thus the CVSS score is 0.0. CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5645</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11528V-Prior to 3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11528V-Prior to 3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5645</Title>
      <Notes>
         <Note Audience="All" Ordinal="9" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Regulatory Reporting with AgileREPORTER product of Oracle Financial Services Applications (component: Core (Apache Ant)).   The supported version that is affected is 8.0.9.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Financial Services Regulatory Reporting with AgileREPORTER.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Regulatory Reporting with AgileREPORTER. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5645</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13077V-8.0.9.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-13077V-8.0.9.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5645</Title>
      <Notes>
         <Note Audience="All" Ordinal="10" Title="Details" Type="Details">Vulnerability in the Identity Manager Connector product of Oracle Fusion Middleware (component: General and Misc (Apache Log4j)).   The supported version that is affected is 9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Identity Manager Connector.  Successful attacks of this vulnerability can result in takeover of Identity Manager Connector. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5645</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1999V-9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1999V-9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5645</Title>
      <Notes>
         <Note Audience="All" Ordinal="11" Title="Details" Type="Details">Security-in-Depth issue in the SQL Developer (Apache Log4j) component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and  18c. This vulnerability cannot be exploited in the context of this product.CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5645</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1875V-11.2.0.4</ProductID>
            <ProductID>P-1875V-12.1.0.2</ProductID>
            <ProductID>P-1875V-12.2.0.1</ProductID>
            <ProductID>P-1875V-18c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1875V-11.2.0.4</ProductID>
            <ProductID>P-1875V-12.1.0.2</ProductID>
            <ProductID>P-1875V-12.2.0.1</ProductID>
            <ProductID>P-1875V-18c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5645</Title>
      <Notes>
         <Note Audience="All" Ordinal="12" Title="Details" Type="Details">Vulnerability in the Oracle TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Install (Apache Log4j)).   The supported version that is affected is Prior to 11.2.2.8.49. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in takeover of Oracle TimesTen In-Memory Database. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5645</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1870V-Prior to 11.2.2.8.49</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1870V-Prior to 11.2.2.8.49</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-7658</Title>
      <Notes>
         <Note Audience="All" Ordinal="13" Title="Details" Type="Details">Vulnerability in the Oracle REST Data Services product of Oracle REST Data Services (component: General (Eclipse Jetty)).  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and  18c. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle REST Data Services.  Successful attacks of this vulnerability can result in takeover of Oracle REST Data Services. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-7658</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9456V-11.2.0.4</ProductID>
            <ProductID>P-9456V-12.1.0.2</ProductID>
            <ProductID>P-9456V-12.2.0.1</ProductID>
            <ProductID>P-9456V-18c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9456V-11.2.0.4</ProductID>
            <ProductID>P-9456V-12.1.0.2</ProductID>
            <ProductID>P-9456V-12.2.0.1</ProductID>
            <ProductID>P-9456V-18c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-9096</Title>
      <Notes>
         <Note Audience="All" Ordinal="14" Title="Details" Type="Details">Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (iText)).  Supported versions that are affected are 16.1, 16.2, 17.7-17.12, 18.8 and  19.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Primavera Unifier. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-9096</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10354V-16.1</ProductID>
            <ProductID>P-10354V-16.2</ProductID>
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10354V-16.1</ProductID>
            <ProductID>P-10354V-16.2</ProductID>
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-9800</Title>
      <Notes>
         <Note Audience="All" Ordinal="15" Title="Details" Type="Details">Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Install, config, upgrade  (Apache HTTP Server)).   The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-9800</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2196V-12.2.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2196V-12.2.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2018-11058</Title>
      <Notes>
         <Note Audience="All" Ordinal="16" Title="Details" Type="Details">Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Web Server Plugin (RSA BSafe)).   The supported version that is affected is 11.1.2.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2018-11058</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5565V-11.1.2.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5565V-11.1.2.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="17" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2018-11058</Title>
      <Notes>
         <Note Audience="All" Ordinal="17" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Load Testing for Web Apps (RSA BSAFE Crypto-C)).   The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite.  Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2018-11058</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-13.3.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4622V-13.3.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="18" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2018-11058</Title>
      <Notes>
         <Note Audience="All" Ordinal="18" Title="Details" Type="Details">Vulnerability in the Oracle GoldenGate Application Adapters product of Oracle Fusion Middleware (component: Security Service (RSA BSAFE)).   The supported version that is affected is 12.3.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle GoldenGate Application Adapters.  Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate Application Adapters. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2018-11058</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5760V-12.3.2.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5760V-12.3.2.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="19" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2018-11058</Title>
      <Notes>
         <Note Audience="All" Ordinal="19" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Weblogic  (RSA BSafe)).  Supported versions that are affected are 8.56, 8.57 and  8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2018-11058</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="20" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2018-11058</Title>
      <Notes>
         <Note Audience="All" Ordinal="20" Title="Details" Type="Details">Vulnerability in the Oracle TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: EM TimesTen plugin (RSA BSAFE Crypto-C)).   The supported version that is affected is Prior to 18.1.4.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in takeover of Oracle TimesTen In-Memory Database. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2018-11058</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1870V-Prior to 18.1.4.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1870V-Prior to 18.1.4.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="21" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2018-17196</Title>
      <Notes>
         <Note Audience="All" Ordinal="21" Title="Details" Type="Details">Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Core (Apache Kafka)).  Supported versions that are affected are 18.8 and  19.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Primavera Unifier accessible data as well as  unauthorized update, insert or delete access to some of Primavera Unifier accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Primavera Unifier. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2018-17196</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="22" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2018-20843</Title>
      <Notes>
         <Note Audience="All" Ordinal="22" Title="Details" Type="Details">Security-in-Depth issue in the Oracle Database (Perl Expat) component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and  19c. This vulnerability cannot be exploited in the context of this product.CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2018-20843</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-18c</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-18c</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="23" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2018-2765</Title>
      <Notes>
         <Note Audience="All" Ordinal="23" Title="Details" Type="Details">Vulnerability in the Oracle SSL API component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.2 and  12.2.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle SSL API.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle SSL API accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2018-2765</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="24" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2018-3693</Title>
      <Notes>
         <Note Audience="All" Ordinal="24" Title="Details" Type="Details">Vulnerability in the Fujitsu M12-1, M12-2, M12-2S Servers product of Oracle Systems (component: XCP Firmware (Kernel)).   The supported version that is affected is Prior to XCP3090. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Fujitsu M12-1, M12-2, M12-2S Servers executes to compromise Fujitsu M12-1, M12-2, M12-2S Servers.  While the vulnerability is in Fujitsu M12-1, M12-2, M12-2S Servers, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Fujitsu M12-1, M12-2, M12-2S Servers accessible data. CVSS 3.1 Base Score 5.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2018-3693</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10656V-Prior to XCP3090</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.6</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10656V-Prior to XCP3090</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="25" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2018-7489</Title>
      <Notes>
         <Note Audience="All" Ordinal="25" Title="Details" Type="Details">Security-in-Depth issue in the SQL Developer (jackson-databind) component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and  18c. This vulnerability cannot be exploited in the context of this product.CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2018-7489</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1875V-11.2.0.4</ProductID>
            <ProductID>P-1875V-12.1.0.2</ProductID>
            <ProductID>P-1875V-12.2.0.1</ProductID>
            <ProductID>P-1875V-18c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1875V-11.2.0.4</ProductID>
            <ProductID>P-1875V-12.1.0.2</ProductID>
            <ProductID>P-1875V-12.2.0.1</ProductID>
            <ProductID>P-1875V-18c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="26" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2018-8013</Title>
      <Notes>
         <Note Audience="All" Ordinal="26" Title="Details" Type="Details">Security-in-Depth issue in the Oracle REST Data Services product of Oracle REST Data Services (component: General (Apache Batik)).  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and  19c. This vulnerability cannot be exploited in the context of this product.CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2018-8013</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9456V-11.2.0.4</ProductID>
            <ProductID>P-9456V-12.1.0.2</ProductID>
            <ProductID>P-9456V-12.2.0.1</ProductID>
            <ProductID>P-9456V-18c</ProductID>
            <ProductID>P-9456V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9456V-11.2.0.4</ProductID>
            <ProductID>P-9456V-12.1.0.2</ProductID>
            <ProductID>P-9456V-12.2.0.1</ProductID>
            <ProductID>P-9456V-18c</ProductID>
            <ProductID>P-9456V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="27" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2018-8013</Title>
      <Notes>
         <Note Audience="All" Ordinal="27" Title="Details" Type="Details">Security-in-Depth issue in the SQL Developer (Apache Batik) component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and  18c. This vulnerability cannot be exploited in the context of this product.CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2018-8013</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1875V-11.2.0.4</ProductID>
            <ProductID>P-1875V-12.1.0.2</ProductID>
            <ProductID>P-1875V-12.2.0.1</ProductID>
            <ProductID>P-1875V-18c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1875V-11.2.0.4</ProductID>
            <ProductID>P-1875V-12.1.0.2</ProductID>
            <ProductID>P-1875V-12.2.0.1</ProductID>
            <ProductID>P-1875V-18c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="28" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2018-8088</Title>
      <Notes>
         <Note Audience="All" Ordinal="28" Title="Details" Type="Details">Vulnerability in the Oracle GoldenGate Application Adapters product of Oracle Fusion Middleware (component: Application Adapters (SLF4J)).   The supported version that is affected is 12.3.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GoldenGate Application Adapters.  Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate Application Adapters. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2018-8088</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5760V-12.3.2.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5760V-12.3.2.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="29" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-0192</Title>
      <Notes>
         <Note Audience="All" Ordinal="29" Title="Details" Type="Details">Vulnerability in the Big Data Spatial and Graph product of Oracle Big Data Graph (component: Property Graph Analytics (Apache Solr)).   The supported version that is affected is Prior to 3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Big Data Spatial and Graph.  Successful attacks of this vulnerability can result in takeover of Big Data Spatial and Graph. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-0192</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11528V-Prior to 3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11528V-Prior to 3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="30" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-0201</Title>
      <Notes>
         <Note Audience="All" Ordinal="30" Title="Details" Type="Details">Vulnerability in the Oracle TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Install (Apache ZooKeeper)).   The supported version that is affected is Prior to 18.1.3.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via ZAB to compromise Oracle TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle TimesTen In-Memory Database accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-0201</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1870V-Prior to 18.1.3.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1870V-Prior to 18.1.3.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="31" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10072</Title>
      <Notes>
         <Note Audience="All" Ordinal="31" Title="Details" Type="Details">Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Mktg/Campaign Mgmt (Apache Tomcat)).   The supported version that is affected is 20.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Marketing.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel Apps - Marketing. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10072</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8974V-20.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8974V-20.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="32" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10097</Title>
      <Notes>
         <Note Audience="All" Ordinal="32" Title="Details" Type="Details">Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Core (Apache HTTP Server)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10097</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1042V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.2</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1042V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="33" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-1010239</Title>
      <Notes>
         <Note Audience="All" Ordinal="33" Title="Details" Type="Details">Vulnerability in the Oracle TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Install (Dave Gamble/cJSON)).   The supported version that is affected is Prior to 18.1.3.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle TimesTen In-Memory Database.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle TimesTen In-Memory Database. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-1010239</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1870V-Prior to 18.1.3.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1870V-Prior to 18.1.3.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="34" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10173</Title>
      <Notes>
         <Note Audience="All" Ordinal="34" Title="Details" Type="Details">Vulnerability in the Oracle Banking Platform product of Oracle Financial Services Applications (component: Collections (xstream)).  Supported versions that are affected are 2.4.0-2.10.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10173</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9178V-2.4.0-2.10.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9178V-2.4.0-2.10.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="35" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10173</Title>
      <Notes>
         <Note Audience="All" Ordinal="35" Title="Details" Type="Details">Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Diameter Gateway and SDK (xstream)).  Supported versions that are affected are 11.3.0.9.0 and  12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications BRM - Elastic Charging Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Communications BRM - Elastic Charging Engine. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10173</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9742V-11.3.0.9.0</ProductID>
            <ProductID>P-9742V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9742V-11.3.0.9.0</ProductID>
            <ProductID>P-9742V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="36" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10173</Title>
      <Notes>
         <Note Audience="All" Ordinal="36" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: IDIH (xstream)).  Supported versions that are affected are IDIH: 8.0.0-8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Diameter Signaling Router (DSR) accessible data as well as  unauthorized read access to a subset of Oracle Communications Diameter Signaling Router (DSR) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Diameter Signaling Router (DSR). CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10173</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="37" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10173</Title>
      <Notes>
         <Note Audience="All" Ordinal="37" Title="Details" Type="Details">Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Core (xstream)).  Supported versions that are affected are 7.3.0 and  7.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10173</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4516V-7.3.0</ProductID>
            <ProductID>P-4516V-7.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4516V-7.3.0</ProductID>
            <ProductID>P-4516V-7.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="38" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10173</Title>
      <Notes>
         <Note Audience="All" Ordinal="38" Title="Details" Type="Details">Vulnerability in the Oracle Endeca Information Discovery Studio product of Oracle Fusion Middleware (component: Endeca Server (xstream)).   The supported version that is affected is 3.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Endeca Information Discovery Studio.  Successful attacks of this vulnerability can result in takeover of Oracle Endeca Information Discovery Studio. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10173</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9634V-3.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9634V-3.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="39" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10173</Title>
      <Notes>
         <Note Audience="All" Ordinal="39" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component: Common (xstream)).  Supported versions that are affected are 2.2.0.0.0, 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0 - 4.3.0.6.0 and  4.4.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Framework. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10173</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2245V-2.2.0.0.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0 - 4.3.0.6.0</ProductID>
            <ProductID>P-2245V-4.4.0.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2245V-2.2.0.0.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0 - 4.3.0.6.0</ProductID>
            <ProductID>P-2245V-4.4.0.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="40" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10173</Title>
      <Notes>
         <Note Audience="All" Ordinal="40" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (xstream)).  Supported versions that are affected are 11.1.1.9.0 and  12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10173</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1696V-11.1.1.9.0</ProductID>
            <ProductID>P-1696V-12.2.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1696V-11.1.1.9.0</ProductID>
            <ProductID>P-1696V-12.2.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="41" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10247</Title>
      <Notes>
         <Note Audience="All" Ordinal="41" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Core Banking product of Oracle Financial Services Applications (component: Core (Eclipse Jetty)).  Supported versions that are affected are 5.2.0 and  11.5.0-11.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Core Banking.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle FLEXCUBE Core Banking accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10247</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9101V-5.2.0</ProductID>
            <ProductID>P-9101V-11.5.0-11.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9101V-5.2.0</ProductID>
            <ProductID>P-9101V-11.5.0-11.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="42" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-10744</Title>
      <Notes>
         <Note Audience="All" Ordinal="42" Title="Details" Type="Details">Security-in-Depth issue in the Big Data Spatial and Graph product of Oracle Big Data Graph (component: Property Graph Analytics (lodash)).   The supported version that is affected is Prior to 20.2. This vulnerability cannot be exploited in the context of this product. Note: CVEs addressed by this patch are not exploitable in the context of Property Graph and Analytics in Big Data Spatial and Graph product, thus the CVSS score is 0.0. CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-10744</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11528V-Prior to 20.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11528V-Prior to 20.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="43" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-11048</Title>
      <Notes>
         <Note Audience="All" Ordinal="43" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: Core (PHP)).  Supported versions that are affected are 8.0.0.0-8.4.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Diameter Signaling Router (DSR). CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-11048</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-8.0.0.0-8.4.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10899V-8.0.0.0-8.4.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="44" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-11358</Title>
      <Notes>
         <Note Audience="All" Ordinal="44" Title="Details" Type="Details">Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security (jQuery)).  Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of BI Publisher accessible data as well as  unauthorized read access to a subset of BI Publisher accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-11358</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="45" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-11358</Title>
      <Notes>
         <Note Audience="All" Ordinal="45" Title="Details" Type="Details">Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Runtime Engine  (jQuery)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Process Management Suite, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Process Management Suite accessible data as well as  unauthorized read access to a subset of Oracle Business Process Management Suite accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-11358</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5325V-12.2.1.3.0</ProductID>
            <ProductID>P-5325V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5325V-12.2.1.3.0</ProductID>
            <ProductID>P-5325V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="46" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-11358</Title>
      <Notes>
         <Note Audience="All" Ordinal="46" Title="Details" Type="Details">Vulnerability in the Oracle Retail Point-of-Service product of Oracle Retail Applications (component: Mobile POS (jQuery)).  Supported versions that are affected are 14.0 and  14.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Point-of-Service.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Point-of-Service, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail Point-of-Service accessible data as well as  unauthorized read access to a subset of Oracle Retail Point-of-Service accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-11358</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2017V-14.0</ProductID>
            <ProductID>P-2017V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2017V-14.0</ProductID>
            <ProductID>P-2017V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="47" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-11477</Title>
      <Notes>
         <Note Audience="All" Ordinal="47" Title="Details" Type="Details">Vulnerability in the Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers product of Oracle Systems (component: XCP Firmware (Linux Kernel)).  Supported versions that are affected are Prior to XCP2362 and  prior to XCP3090. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Fujitsu M10-1, M10-4, M10-4S, M12-1, M12-2, M12-2S Servers. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-11477</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10656V-Prior to XCP2362</ProductID>
            <ProductID>P-10656V-prior to XCP3090</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10656V-Prior to XCP2362</ProductID>
            <ProductID>P-10656V-prior to XCP3090</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="48" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-11922</Title>
      <Notes>
         <Note Audience="All" Ordinal="48" Title="Details" Type="Details">Security-in-Depth issue in the Core RDBMS (Zstandard) component of Oracle Database Server.   The supported version that is affected is 19c. This vulnerability cannot be exploited in the context of this product.CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-11922</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="49" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-12260</Title>
      <Notes>
         <Note Audience="All" Ordinal="49" Title="Details" Type="Details">Vulnerability in the Oracle Communications EAGLE Software product of Oracle Communications (component: Network Stack (Wind River VxWorks)).  Supported versions that are affected are 46.6.0-46.8.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications EAGLE Software.  Successful attacks of this vulnerability can result in takeover of Oracle Communications EAGLE Software. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-12260</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10768V-46.6.0-46.8.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10768V-46.6.0-46.8.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="50" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-12402</Title>
      <Notes>
         <Note Audience="All" Ordinal="50" Title="Details" Type="Details">Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Core (Apache Commons Compress)).  Supported versions that are affected are 8.2.0-8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Element Manager. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-12402</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11052V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11052V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="51" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-12402</Title>
      <Notes>
         <Note Audience="All" Ordinal="51" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: Core (Apache Commons Compress)).  Supported versions that are affected are 8.2.0-8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Report Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-12402</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10770V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10770V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="52" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-12402</Title>
      <Notes>
         <Note Audience="All" Ordinal="52" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Route Manager product of Oracle Communications (component: Core (Apache Commons Compress)).  Supported versions that are affected are 8.2.0-8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Route Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Route Manager. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-12402</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10771V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10771V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="53" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-12415</Title>
      <Notes>
         <Note Audience="All" Ordinal="53" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: IDIH (Apache POI)).  Supported versions that are affected are IDIH: 8.0.0-8.2.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Diameter Signaling Router (DSR) executes to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router (DSR) accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-12415</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="54" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-12415</Title>
      <Notes>
         <Note Audience="All" Ordinal="54" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Broker product of Oracle Retail Applications (component: Store Connect (Apache POI)).  Supported versions that are affected are 15.0 and  16.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Order Broker executes to compromise Oracle Retail Order Broker.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Order Broker accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-12415</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11520V-15.0</ProductID>
            <ProductID>P-11520V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11520V-15.0</ProductID>
            <ProductID>P-11520V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="55" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-12900</Title>
      <Notes>
         <Note Audience="All" Ordinal="55" Title="Details" Type="Details">Vulnerability in the Core RDBMS (bzip2) component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and  19c. Easily exploitable vulnerability allows low privileged attacker having DBA Level Account privilege with network access via Oracle Net to compromise Core RDBMS (bzip2).  Successful attacks of this vulnerability can result in takeover of Core RDBMS (bzip2). CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-12900</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-18c</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-18c</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="56" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-13990</Title>
      <Notes>
         <Note Audience="All" Ordinal="56" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Route Manager product of Oracle Communications (component: Core (Quartz Scheduler)).  Supported versions that are affected are 8.2.0-8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Route Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Route Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-13990</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10771V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10771V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="57" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-13990</Title>
      <Notes>
         <Note Audience="All" Ordinal="57" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center product of Oracle Enterprise Manager (component: Agent Provisioning (Quartz Scheduler)).   The supported version that is affected is 12.4.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Ops Center.  Successful attacks of this vulnerability can result in takeover of Enterprise Manager Ops Center. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-13990</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-12.4.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9835V-12.4.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="58" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-1547</Title>
      <Notes>
         <Note Audience="All" Ordinal="58" Title="Details" Type="Details">Vulnerability in the Hyperion Essbase product of Oracle Hyperion (component: Security and Provisioning (OpenSSL)).   The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Hyperion Essbase executes to compromise Hyperion Essbase.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Hyperion Essbase accessible data. CVSS 3.1 Base Score 4.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-1547</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4379V-11.1.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4379V-11.1.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="59" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-16335</Title>
      <Notes>
         <Note Audience="All" Ordinal="59" Title="Details" Type="Details">Security-in-Depth issue in the Oracle REST Data Services product of Oracle REST Data Services (component: General (jackson-databind)).  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and  19c. This vulnerability cannot be exploited in the context of this product.CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-16335</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9456V-11.2.0.4</ProductID>
            <ProductID>P-9456V-12.1.0.2</ProductID>
            <ProductID>P-9456V-12.2.0.1</ProductID>
            <ProductID>P-9456V-18c</ProductID>
            <ProductID>P-9456V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9456V-11.2.0.4</ProductID>
            <ProductID>P-9456V-12.1.0.2</ProductID>
            <ProductID>P-9456V-12.2.0.1</ProductID>
            <ProductID>P-9456V-18c</ProductID>
            <ProductID>P-9456V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="60" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-16943</Title>
      <Notes>
         <Note Audience="All" Ordinal="60" Title="Details" Type="Details">Security-in-Depth issue in the Oracle Spatial and Graph (jackson-databind) component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and  18c. This vulnerability cannot be exploited in the context of this product. Note: CVE-2019-16943, and additional CVEs addressed by this patch, are not exploitable in the context of Oracle Spatial and Graph, Property Graph Analytics, so the CVSS scores are all 0.0. Also, CVE-2019-16943 only applies to Windows platforms. CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-16943</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-619V-11.2.0.4</ProductID>
            <ProductID>P-619V-12.1.0.2</ProductID>
            <ProductID>P-619V-12.2.0.1</ProductID>
            <ProductID>P-619V-18c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-619V-11.2.0.4</ProductID>
            <ProductID>P-619V-12.1.0.2</ProductID>
            <ProductID>P-619V-12.2.0.1</ProductID>
            <ProductID>P-619V-18c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="61" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17091</Title>
      <Notes>
         <Note Audience="All" Ordinal="61" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: Platform (Eclipse Mojarra)).  Supported versions that are affected are 8.0.0.0-8.4.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Diameter Signaling Router (DSR), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Diameter Signaling Router (DSR) accessible data as well as  unauthorized read access to a subset of Oracle Communications Diameter Signaling Router (DSR) accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17091</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-8.0.0.0-8.4.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10899V-8.0.0.0-8.4.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="62" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17267</Title>
      <Notes>
         <Note Audience="All" Ordinal="62" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars  (jackson-databind)).   The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17267</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="63" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17359</Title>
      <Notes>
         <Note Audience="All" Ordinal="63" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: IDIH (Bouncy Castle Java Library)).  Supported versions that are affected are IDIH: 8.0.0-8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Diameter Signaling Router (DSR). CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17359</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="64" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17359</Title>
      <Notes>
         <Note Audience="All" Ordinal="64" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Route Manager product of Oracle Communications (component: Core (Bouncy Castle Java Library)).  Supported versions that are affected are 8.2.0-8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Communications Session Route Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Route Manager. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17359</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10771V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10771V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="65" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17359</Title>
      <Notes>
         <Note Audience="All" Ordinal="65" Title="Details" Type="Details">Security-in-Depth issue in the SQL Developer Install (Bouncy Castle) component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and  18c. This vulnerability cannot be exploited in the context of this product.CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17359</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1875V-11.2.0.4</ProductID>
            <ProductID>P-1875V-12.1.0.2</ProductID>
            <ProductID>P-1875V-12.2.0.1</ProductID>
            <ProductID>P-1875V-18c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1875V-11.2.0.4</ProductID>
            <ProductID>P-1875V-12.1.0.2</ProductID>
            <ProductID>P-1875V-12.2.0.1</ProductID>
            <ProductID>P-1875V-18c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="66" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17495</Title>
      <Notes>
         <Note Audience="All" Ordinal="66" Title="Details" Type="Details">Vulnerability in the Oracle Banking Platform product of Oracle Financial Services Applications (component: Collections (Swagger UI)).  Supported versions that are affected are 2.4.0-2.10.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17495</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9178V-2.4.0-2.10.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9178V-2.4.0-2.10.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="67" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17495</Title>
      <Notes>
         <Note Audience="All" Ordinal="67" Title="Details" Type="Details">Vulnerability in the Primavera Gateway product of Oracle Construction and Engineering (component: Admin (Swagger UI)).  Supported versions that are affected are 16.2.0-16.2.11 and  17.12.0-17.12.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Gateway.  Successful attacks of this vulnerability can result in takeover of Primavera Gateway. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17495</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10605V-16.2.0-16.2.11</ProductID>
            <ProductID>P-10605V-17.12.0-17.12.8</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10605V-16.2.0-16.2.11</ProductID>
            <ProductID>P-10605V-17.12.0-17.12.8</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="68" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17531</Title>
      <Notes>
         <Note Audience="All" Ordinal="68" Title="Details" Type="Details">Vulnerability in the Oracle GoldenGate Application Adapters product of Oracle Fusion Middleware (component: Build Request (jackson-databind)).   The supported version that is affected is 19.1.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GoldenGate Application Adapters.  Successful attacks of this vulnerability can result in takeover of Oracle GoldenGate Application Adapters. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17531</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5760V-19.1.0.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5760V-19.1.0.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="69" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17543</Title>
      <Notes>
         <Note Audience="All" Ordinal="69" Title="Details" Type="Details">Security-in-Depth issue in the Core RDBMS (LZ4) component of Oracle Database Server.   The supported version that is affected is 19c. This vulnerability cannot be exploited in the context of this product.CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17543</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="70" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17558</Title>
      <Notes>
         <Note Audience="All" Ordinal="70" Title="Details" Type="Details">Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (Apache Solr)).  Supported versions that are affected are 16.1, 16.2, 17.7-17.12, 18.8 and  19.12. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in takeover of Primavera Unifier. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17558</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10354V-16.1</ProductID>
            <ProductID>P-10354V-16.2</ProductID>
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10354V-16.1</ProductID>
            <ProductID>P-10354V-16.2</ProductID>
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="71" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17638</Title>
      <Notes>
         <Note Audience="All" Ordinal="71" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Load Testing for Web Apps (Eclipse Jetty)).   The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Application Testing Suite accessible data as well as  unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-13.3.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.4</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4622V-13.3.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="72" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17638</Title>
      <Notes>
         <Note Audience="All" Ordinal="72" Title="Details" Type="Details">Vulnerability in the Oracle Communications Application Session Controller product of Oracle Communications (component: WS and WEB (Eclipse Jetty)).   The supported version that is affected is 3.9m0p1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Application Session Controller.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Application Session Controller accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Application Session Controller accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Application Session Controller. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10769V-3.9m0p1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.4</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10769V-3.9m0p1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="73" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17638</Title>
      <Notes>
         <Note Audience="All" Ordinal="73" Title="Details" Type="Details">Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Core (Eclipse Jetty)).  Supported versions that are affected are 8.2.0-8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Element Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Element Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Element Manager. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11052V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.4</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11052V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="74" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17638</Title>
      <Notes>
         <Note Audience="All" Ordinal="74" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: Core (Eclipse Jetty)).  Supported versions that are affected are 8.2.0-8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Report Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Session Report Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Session Report Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10770V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.4</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10770V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="75" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17638</Title>
      <Notes>
         <Note Audience="All" Ordinal="75" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Route Manager product of Oracle Communications (component: Core (Eclipse Jetty)).  Supported versions that are affected are 8.2.0-8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Route Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Session Route Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Session Route Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Session Route Manager. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10771V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.4</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10771V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="76" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-17638</Title>
      <Notes>
         <Note Audience="All" Ordinal="76" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality Guest Access product of Oracle Hospitality Applications (component: Base (Eclipse Jetty)).  Supported versions that are affected are 4.2.0 and  4.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Guest Access.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality Guest Access accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hospitality Guest Access accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality Guest Access. CVSS 3.1 Base Score 9.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-17638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12617V-4.2.0</ProductID>
            <ProductID>P-12617V-4.2.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.4</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-12617V-4.2.0</ProductID>
            <ProductID>P-12617V-4.2.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="77" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-2897</Title>
      <Notes>
         <Note Audience="All" Ordinal="77" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management).  Supported versions that are affected are 13.3.0.0 and  13.4.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Manager Base Platform.  While the vulnerability is in Enterprise Manager Base Platform, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Enterprise Manager Base Platform accessible data as well as  unauthorized read access to a subset of Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-2897</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-13.3.0.0</ProductID>
            <ProductID>P-1370V-13.4.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1370V-13.3.0.0</ProductID>
            <ProductID>P-1370V-13.4.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="78" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-2904</Title>
      <Notes>
         <Note Audience="All" Ordinal="78" Title="Details" Type="Details">Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Runtime Engine (Application Development Framework)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Process Management Suite.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Process Management Suite, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Process Management Suite accessible data as well as  unauthorized read access to a subset of Oracle Business Process Management Suite accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-2904</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5325V-12.2.1.3.0</ProductID>
            <ProductID>P-5325V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5325V-12.2.1.3.0</ProductID>
            <ProductID>P-5325V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="79" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-2904</Title>
      <Notes>
         <Note Audience="All" Ordinal="79" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: Platform (Application Development Framework)).  Supported versions that are affected are 8.0.0.0-8.4.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router (DSR). CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-2904</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-8.0.0.0-8.4.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10899V-8.0.0.0-8.4.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="80" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-2904</Title>
      <Notes>
         <Note Audience="All" Ordinal="80" Title="Details" Type="Details">Vulnerability in the Oracle Enterprise Repository product of Oracle Fusion Middleware (component: Security Subsystem - 12c (Application Development Framework)).   The supported version that is affected is 11.1.1.7.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Repository. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-2904</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5326V-11.1.1.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5326V-11.1.1.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="81" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-3740</Title>
      <Notes>
         <Note Audience="All" Ordinal="81" Title="Details" Type="Details">Vulnerability in the Application Performance Management (APM) product of Oracle Enterprise Manager (component: Comp Management and Life Cycle Management (RSA BSAFE Crypto-J)).  Supported versions that are affected are 13.3.0.0 and  13.4.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Application Performance Management (APM).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Application Performance Management (APM) accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-3740</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9572V-13.3.0.0</ProductID>
            <ProductID>P-9572V-13.4.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9572V-13.3.0.0</ProductID>
            <ProductID>P-9572V-13.4.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="82" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-3740</Title>
      <Notes>
         <Note Audience="All" Ordinal="82" Title="Details" Type="Details">Vulnerability in the Oracle Retail Assortment Planning product of Oracle Retail Applications (component: Application Core (RSA BSAFE Crypto-J)).  Supported versions that are affected are 15.0.3.0 and  16.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Assortment Planning.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Assortment Planning accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-3740</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1788V-15.0.3.0</ProductID>
            <ProductID>P-1788V-16.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1788V-15.0.3.0</ProductID>
            <ProductID>P-1788V-16.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="83" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-3740</Title>
      <Notes>
         <Note Audience="All" Ordinal="83" Title="Details" Type="Details">Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (RSA BSAFE Crypto-J)).  Supported versions that are affected are 14.1, 15.0 and  16.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Integration Bus accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-3740</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1807V-14.1</ProductID>
            <ProductID>P-1807V-15.0</ProductID>
            <ProductID>P-1807V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1807V-14.1</ProductID>
            <ProductID>P-1807V-15.0</ProductID>
            <ProductID>P-1807V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="84" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-3740</Title>
      <Notes>
         <Note Audience="All" Ordinal="84" Title="Details" Type="Details">Vulnerability in the Oracle Retail Predictive Application Server product of Oracle Retail Applications (component: RPAS Server (RSA BSAFE Crypto-J)).  Supported versions that are affected are 14.1.3.0, 15.0.3.0 and  16.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Predictive Application Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Predictive Application Server accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-3740</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1823V-14.1.3.0</ProductID>
            <ProductID>P-1823V-15.0.3.0</ProductID>
            <ProductID>P-1823V-16.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1823V-14.1.3.0</ProductID>
            <ProductID>P-1823V-15.0.3.0</ProductID>
            <ProductID>P-1823V-16.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="85" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-3740</Title>
      <Notes>
         <Note Audience="All" Ordinal="85" Title="Details" Type="Details">Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB kernel (RSA BSAFE Crypto-J)).  Supported versions that are affected are 14.1, 15.0 and  16.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Service Backbone accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-3740</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10867V-14.1</ProductID>
            <ProductID>P-10867V-15.0</ProductID>
            <ProductID>P-10867V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10867V-14.1</ProductID>
            <ProductID>P-10867V-15.0</ProductID>
            <ProductID>P-10867V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="86" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-3740</Title>
      <Notes>
         <Note Audience="All" Ordinal="86" Title="Details" Type="Details">Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xenvironment (RSA BSAFE Crypto-J)).  Supported versions that are affected are 15.0.3, 
16.0.5, 
17.0.3, 
18.0.2 and  19.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Xstore Point of Service.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Xstore Point of Service accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-3740</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11513V-15.0.3</ProductID>
            <ProductID>P-11513V-16.0.5</ProductID>
            <ProductID>P-11513V-17.0.3</ProductID>
            <ProductID>P-11513V-18.0.2</ProductID>
            <ProductID>P-11513V-19.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11513V-15.0.3</ProductID>
            <ProductID>P-11513V-16.0.5</ProductID>
            <ProductID>P-11513V-17.0.3</ProductID>
            <ProductID>P-11513V-18.0.2</ProductID>
            <ProductID>P-11513V-19.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="87" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-5482</Title>
      <Notes>
         <Note Audience="All" Ordinal="87" Title="Details" Type="Details">Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: Web Listener (cURL)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TFTP to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in takeover of Oracle HTTP Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-5482</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1042V-12.2.1.3.0</ProductID>
            <ProductID>P-1042V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1042V-12.2.1.3.0</ProductID>
            <ProductID>P-1042V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="88" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2019-5482</Title>
      <Notes>
         <Note Audience="All" Ordinal="88" Title="Details" Type="Details">Vulnerability in the Hyperion Essbase product of Oracle Hyperion (component: Security and Provisioning (cURL)).   The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via TFTP to compromise Hyperion Essbase.  Successful attacks of this vulnerability can result in takeover of Hyperion Essbase. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2019-5482</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4379V-11.1.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4379V-11.1.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="89" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10683</Title>
      <Notes>
         <Note Audience="All" Ordinal="89" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Security (dom4j)).  Supported versions that are affected are 9.3.3 and  9.3.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.3</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4461V-9.3.3</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="90" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10683</Title>
      <Notes>
         <Note Audience="All" Ordinal="90" Title="Details" Type="Details">Vulnerability in the Oracle Banking Platform product of Oracle Financial Services Applications (component: Collections (dom4j)).  Supported versions that are affected are 2.4.0-2.10.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9178V-2.4.0-2.10.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9178V-2.4.0-2.10.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="91" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10683</Title>
      <Notes>
         <Note Audience="All" Ordinal="91" Title="Details" Type="Details">Vulnerability in the Oracle Communications Application Session Controller product of Oracle Communications (component: WS and WEB (dom4j)).   The supported version that is affected is 3.9m0p1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Communications Application Session Controller.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Application Session Controller. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10769V-3.9m0p1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10769V-3.9m0p1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="92" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10683</Title>
      <Notes>
         <Note Audience="All" Ordinal="92" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: IDIH (dom4j)).  Supported versions that are affected are IDIH: 8.0.0-8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router (DSR). CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="93" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10683</Title>
      <Notes>
         <Note Audience="All" Ordinal="93" Title="Details" Type="Details">Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Core (dom4j)).  Supported versions that are affected are 7.3.0 and  7.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Inventory Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4516V-7.3.0</ProductID>
            <ProductID>P-4516V-7.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4516V-7.3.0</ProductID>
            <ProductID>P-4516V-7.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="94" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10683</Title>
      <Notes>
         <Note Audience="All" Ordinal="94" Title="Details" Type="Details">Vulnerability in the Oracle Endeca Information Discovery Integrator product of Oracle Fusion Middleware (component: Integrator ETL (dom4j)).   The supported version that is affected is 3.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Endeca Information Discovery Integrator.  Successful attacks of this vulnerability can result in takeover of Oracle Endeca Information Discovery Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10561V-3.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10561V-3.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="95" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10683</Title>
      <Notes>
         <Note Audience="All" Ordinal="95" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (dom4j)).  Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5680V-8.0.6-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5680V-8.0.6-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="96" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10683</Title>
      <Notes>
         <Note Audience="All" Ordinal="96" Title="Details" Type="Details">Vulnerability in the Oracle Health Sciences Empirica Signal product of Oracle Health Sciences Applications (component: User Interface (dom4j)).   The supported version that is affected is 9.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Health Sciences Empirica Signal.  Successful attacks of this vulnerability can result in takeover of Oracle Health Sciences Empirica Signal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9646V-9.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9646V-9.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="97" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10683</Title>
      <Notes>
         <Note Audience="All" Ordinal="97" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Broker product of Oracle Retail Applications (component: System Administration (dom4j)).  Supported versions that are affected are 15.0, 16.0, 18.0, 19.0 and  19.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Order Broker.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Order Broker. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11520V-15.0</ProductID>
            <ProductID>P-11520V-16.0</ProductID>
            <ProductID>P-11520V-18.0</ProductID>
            <ProductID>P-11520V-19.0</ProductID>
            <ProductID>P-11520V-19.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11520V-15.0</ProductID>
            <ProductID>P-11520V-16.0</ProductID>
            <ProductID>P-11520V-18.0</ProductID>
            <ProductID>P-11520V-19.0</ProductID>
            <ProductID>P-11520V-19.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="98" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10683</Title>
      <Notes>
         <Note Audience="All" Ordinal="98" Title="Details" Type="Details">Vulnerability in the Oracle Retail Price Management product of Oracle Retail Applications (component: Security (dom4j)).  Supported versions that are affected are 14.0.4, 14.1.3.0, 15.0.3.0 and  16.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Price Management.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Price Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1824V-14.0.4</ProductID>
            <ProductID>P-1824V-14.1.3.0</ProductID>
            <ProductID>P-1824V-15.0.3.0</ProductID>
            <ProductID>P-1824V-16.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1824V-14.0.4</ProductID>
            <ProductID>P-1824V-14.1.3.0</ProductID>
            <ProductID>P-1824V-15.0.3.0</ProductID>
            <ProductID>P-1824V-16.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="99" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10683</Title>
      <Notes>
         <Note Audience="All" Ordinal="99" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component: General (dom4j)).  Supported versions that are affected are 2.2.0.0.0, 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0 - 4.3.0.6.0, 4.4.0.0.0 and  4.4.0.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Framework. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2245V-2.2.0.0.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0 - 4.3.0.6.0</ProductID>
            <ProductID>P-2245V-4.4.0.0.0</ProductID>
            <ProductID>P-2245V-4.4.0.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2245V-2.2.0.0.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0 - 4.3.0.6.0</ProductID>
            <ProductID>P-2245V-4.4.0.0.0</ProductID>
            <ProductID>P-2245V-4.4.0.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="100" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10683</Title>
      <Notes>
         <Note Audience="All" Ordinal="100" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services (dom4j)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10683</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1696V-12.2.1.3.0</ProductID>
            <ProductID>P-1696V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1696V-12.2.1.3.0</ProductID>
            <ProductID>P-1696V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="101" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10722</Title>
      <Notes>
         <Note Audience="All" Ordinal="101" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: Platform (DPDK)).  Supported versions that are affected are 8.2-8.4. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Session Border Controller executes to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Border Controller. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10722</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10750V-8.2-8.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.7</BaseScore>
            <Vector>AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10750V-8.2-8.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="102" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-10878</Title>
      <Notes>
         <Note Audience="All" Ordinal="102" Title="Details" Type="Details">Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Core (Perl)).  Supported versions that are affected are 12.0.0.2.0 and  12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Billing and Revenue Management as well as  unauthorized update, insert or delete access to some of Oracle Communications Billing and Revenue Management accessible data and  unauthorized read access to a subset of Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-10878</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2136V-12.0.0.2.0</ProductID>
            <ProductID>P-2136V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2136V-12.0.0.2.0</ProductID>
            <ProductID>P-2136V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="103" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="103" Title="Details" Type="Details">Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Supplier Portal (jQuery)).   The supported version that is affected is 6.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile Product Lifecycle Management for Process.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile Product Lifecycle Management for Process, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile Product Lifecycle Management for Process accessible data as well as  unauthorized read access to a subset of Oracle Agile Product Lifecycle Management for Process accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4447V-6.2.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4447V-6.2.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="104" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="104" Title="Details" Type="Details">Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: Framework (jQuery)).  Supported versions that are affected are 18.1, 18.2, 18.3, 19.1, 19.2 and  20.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Digital Experience.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Digital Experience, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Banking Digital Experience accessible data as well as  unauthorized read access to a subset of Oracle Banking Digital Experience accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12605V-18.1</ProductID>
            <ProductID>P-12605V-18.2</ProductID>
            <ProductID>P-12605V-18.3</ProductID>
            <ProductID>P-12605V-19.1</ProductID>
            <ProductID>P-12605V-19.2</ProductID>
            <ProductID>P-12605V-20.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-12605V-18.1</ProductID>
            <ProductID>P-12605V-18.2</ProductID>
            <ProductID>P-12605V-18.3</ProductID>
            <ProductID>P-12605V-19.1</ProductID>
            <ProductID>P-12605V-19.2</ProductID>
            <ProductID>P-12605V-20.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="105" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="105" Title="Details" Type="Details">Vulnerability in the Oracle Communications Application Session Controller product of Oracle Communications (component: Core (jQuery)).   The supported version that is affected is 3.8m0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Application Session Controller.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Application Session Controller, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Application Session Controller accessible data as well as  unauthorized read access to a subset of Oracle Communications Application Session Controller accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10769V-3.8m0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10769V-3.8m0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="106" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="106" Title="Details" Type="Details">Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Operation Center and Oracle Communication Billing Care (jQuery)).  Supported versions that are affected are 7.5.0.23.0 and  12.0.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Billing and Revenue Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Billing and Revenue Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Billing and Revenue Management accessible data as well as  unauthorized read access to a subset of Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2136V-7.5.0.23.0</ProductID>
            <ProductID>P-2136V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2136V-7.5.0.23.0</ProductID>
            <ProductID>P-2136V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="107" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="107" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: IDIH (jQuery)).  Supported versions that are affected are IDIH: 8.0.0-8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Diameter Signaling Router (DSR), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Diameter Signaling Router (DSR) accessible data as well as  unauthorized read access to a subset of Oracle Communications Diameter Signaling Router (DSR) accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="108" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="108" Title="Details" Type="Details">Vulnerability in the Oracle Communications WebRTC Session Controller product of Oracle Communications (component: ME (jQuery)).   The supported version that is affected is 7.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications WebRTC Session Controller.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications WebRTC Session Controller, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications WebRTC Session Controller accessible data as well as  unauthorized read access to a subset of Oracle Communications WebRTC Session Controller accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10811V-7.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10811V-7.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="109" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="109" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Ops Center product of Oracle Enterprise Manager (component: Reports in Ops Center (jQuery)).   The supported version that is affected is 12.4.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Ops Center.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Enterprise Manager Ops Center, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Enterprise Manager Ops Center accessible data as well as  unauthorized read access to a subset of Enterprise Manager Ops Center accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9835V-12.4.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9835V-12.4.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="110" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="110" Title="Details" Type="Details">Vulnerability in the Oracle Enterprise Session Border Controller product of Oracle Communications (component: Core (jQuery)).   The supported version that is affected is 8.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Session Border Controller.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Enterprise Session Border Controller, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Session Border Controller accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Session Border Controller accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10757V-8.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10757V-8.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="111" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="111" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (jQuery)).  Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Infrastructure accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5680V-8.0.6-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5680V-8.0.6-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="112" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="112" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Analytical Applications Reconciliation Framework product of Oracle Financial Services Applications (component: User Interface (jQuery)).  Supported versions that are affected are 8.0.6-8.0.8 and  8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Reconciliation Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Analytical Applications Reconciliation Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Analytical Applications Reconciliation Framework accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Analytical Applications Reconciliation Framework accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5748V-8.0.6-8.0.8</ProductID>
            <ProductID>P-5748V-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5748V-8.0.6-8.0.8</ProductID>
            <ProductID>P-5748V-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="113" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="113" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Asset Liability Management product of Oracle Financial Services Applications (component: User Interface (jQuery)).  Supported versions that are affected are 8.0.6, 8.0.7 and  8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Asset Liability Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Asset Liability Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Asset Liability Management accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Asset Liability Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5662V-8.0.6</ProductID>
            <ProductID>P-5662V-8.0.7</ProductID>
            <ProductID>P-5662V-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5662V-8.0.6</ProductID>
            <ProductID>P-5662V-8.0.7</ProductID>
            <ProductID>P-5662V-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="114" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="114" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Balance Sheet Planning product of Oracle Financial Services Applications (component: User Interface (jQuery)).   The supported version that is affected is 8.0.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Balance Sheet Planning.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Balance Sheet Planning, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Balance Sheet Planning accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Balance Sheet Planning accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5663V-8.0.8</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5663V-8.0.8</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="115" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="115" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Basel Regulatory Capital Basic product of Oracle Financial Services Applications (component: User Interface (jQuery)).  Supported versions that are affected are 8.0.6-8.0.8 and  8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Basel Regulatory Capital Basic.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Basel Regulatory Capital Basic, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Basel Regulatory Capital Basic accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Basel Regulatory Capital Basic accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9612V-8.0.6-8.0.8</ProductID>
            <ProductID>P-9612V-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9612V-8.0.6-8.0.8</ProductID>
            <ProductID>P-9612V-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="116" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="116" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach product of Oracle Financial Services Applications (component: User Interface  (jQuery)).  Supported versions that are affected are 8.0.6-8.0.8 and  8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9450V-8.0.6-8.0.8</ProductID>
            <ProductID>P-9450V-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9450V-8.0.6-8.0.8</ProductID>
            <ProductID>P-9450V-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="117" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="117" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Data Foundation product of Oracle Financial Services Applications (component: Infrastructure (jQuery)).  Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Data Foundation.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Data Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Data Foundation accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Data Foundation accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9180V-8.0.6-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9180V-8.0.6-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="118" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="118" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Data Governance for US Regulatory Reporting product of Oracle Financial Services Applications (component: User Interface (jQuery)).  Supported versions that are affected are 8.0.6-8.0.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Data Governance for US Regulatory Reporting.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Data Governance for US Regulatory Reporting, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Data Governance for US Regulatory Reporting accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Data Governance for US Regulatory Reporting accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11669V-8.0.6-8.0.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11669V-8.0.6-8.0.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="119" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="119" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Data Integration Hub product of Oracle Financial Services Applications (component: User Interface (jQuery)).  Supported versions that are affected are 8.0.6, 8.0.7 and  8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Data Integration Hub.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Data Integration Hub, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Data Integration Hub accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Data Integration Hub accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11289V-8.0.6</ProductID>
            <ProductID>P-11289V-8.0.7</ProductID>
            <ProductID>P-11289V-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11289V-8.0.6</ProductID>
            <ProductID>P-11289V-8.0.7</ProductID>
            <ProductID>P-11289V-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="120" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="120" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Funds Transfer Pricing product of Oracle Financial Services Applications (component: User Interface (jQuery)).  Supported versions that are affected are 8.0.6, 8.0.7 and  8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Funds Transfer Pricing.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Funds Transfer Pricing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Funds Transfer Pricing accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Funds Transfer Pricing accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5659V-8.0.6</ProductID>
            <ProductID>P-5659V-8.0.7</ProductID>
            <ProductID>P-5659V-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5659V-8.0.6</ProductID>
            <ProductID>P-5659V-8.0.7</ProductID>
            <ProductID>P-5659V-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="121" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="121" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations product of Oracle Financial Services Applications (component: User Interface (jQuery)).  Supported versions that are affected are 8.0.6-8.0.8 and  8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Hedge Management and IFRS Valuations.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Hedge Management and IFRS Valuations, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Hedge Management and IFRS Valuations accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Hedge Management and IFRS Valuations accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9332V-8.0.6-8.0.8</ProductID>
            <ProductID>P-9332V-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9332V-8.0.6-8.0.8</ProductID>
            <ProductID>P-9332V-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="122" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="122" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Institutional Performance Analytics product of Oracle Financial Services Applications (component: User Interface (jQuery)).  Supported versions that are affected are 8.0.6, 8.0.7 and  8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Institutional Performance Analytics.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Institutional Performance Analytics, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Institutional Performance Analytics accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Institutional Performance Analytics accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10215V-8.0.6</ProductID>
            <ProductID>P-10215V-8.0.7</ProductID>
            <ProductID>P-10215V-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10215V-8.0.6</ProductID>
            <ProductID>P-10215V-8.0.7</ProductID>
            <ProductID>P-10215V-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="123" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="123" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Liquidity Risk Management product of Oracle Financial Services Applications (component: User Interface (jQuery)).   The supported version that is affected is 8.0.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Liquidity Risk Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Liquidity Risk Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Liquidity Risk Management accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Liquidity Risk Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9096V-8.0.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9096V-8.0.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="124" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="124" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Liquidity Risk Measurement and Management product of Oracle Financial Services Applications (component: User Interface (jQuery)).  Supported versions that are affected are 8.0.7, 8.0.8 and  8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Liquidity Risk Measurement and Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Liquidity Risk Measurement and Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Liquidity Risk Measurement and Management accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Liquidity Risk Measurement and Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13797V-8.0.7</ProductID>
            <ProductID>P-13797V-8.0.8</ProductID>
            <ProductID>P-13797V-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-13797V-8.0.7</ProductID>
            <ProductID>P-13797V-8.0.8</ProductID>
            <ProductID>P-13797V-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="125" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="125" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning product of Oracle Financial Services Applications (component: User Interface (jQuery)).  Supported versions that are affected are 8.0.6-8.0.8 and  8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Loan Loss Forecasting and Provisioning.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Loan Loss Forecasting and Provisioning, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Loan Loss Forecasting and Provisioning accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Loan Loss Forecasting and Provisioning accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9474V-8.0.6-8.0.8</ProductID>
            <ProductID>P-9474V-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9474V-8.0.6-8.0.8</ProductID>
            <ProductID>P-9474V-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="126" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="126" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Market Risk Measurement and Management product of Oracle Financial Services Applications (component: Infrastructure (jQuery)).  Supported versions that are affected are 8.0.6 and  8.0.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Market Risk Measurement and Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Market Risk Measurement and Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Market Risk Measurement and Management accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Market Risk Measurement and Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13111V-8.0.6</ProductID>
            <ProductID>P-13111V-8.0.8</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-13111V-8.0.6</ProductID>
            <ProductID>P-13111V-8.0.8</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="127" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="127" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Price Creation and Discovery product of Oracle Financial Services Applications (component: User Interface (jQuery)).  Supported versions that are affected are 8.0.6 and  8.0.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Price Creation and Discovery.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Price Creation and Discovery, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Price Creation and Discovery accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Price Creation and Discovery accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5749V-8.0.6</ProductID>
            <ProductID>P-5749V-8.0.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5749V-8.0.6</ProductID>
            <ProductID>P-5749V-8.0.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="128" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="128" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Profitability Management product of Oracle Financial Services Applications (component: User Interface (jQuery)).  Supported versions that are affected are 8.0.6, 8.0.7 and  8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Profitability Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Profitability Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Profitability Management accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Profitability Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5658V-8.0.6</ProductID>
            <ProductID>P-5658V-8.0.7</ProductID>
            <ProductID>P-5658V-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5658V-8.0.6</ProductID>
            <ProductID>P-5658V-8.0.7</ProductID>
            <ProductID>P-5658V-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="129" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="129" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Regulatory Reporting for European Banking Authority product of Oracle Financial Services Applications (component: User Interface (jQuery)).  Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Regulatory Reporting for European Banking Authority.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Regulatory Reporting for European Banking Authority, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Regulatory Reporting for European Banking Authority accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Regulatory Reporting for European Banking Authority accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13147V-8.0.6-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-13147V-8.0.6-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="130" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="130" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Regulatory Reporting for US Federal Reserve product of Oracle Financial Services Applications (component: User Interface (jQuery)).  Supported versions that are affected are 8.0.6-8.0.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Regulatory Reporting for US Federal Reserve.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Financial Services Regulatory Reporting for US Federal Reserve, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Financial Services Regulatory Reporting for US Federal Reserve accessible data as well as  unauthorized read access to a subset of Oracle Financial Services Regulatory Reporting for US Federal Reserve accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13080V-8.0.6-8.0.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-13080V-8.0.6-8.0.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="131" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="131" Title="Details" Type="Details">Vulnerability in the Oracle Healthcare Foundation product of Oracle Health Sciences Applications (component: Admin Console (jQuery)).  Supported versions that are affected are 7.1.1, 7.2.0, 7.2.1 and  7.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Foundation.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Healthcare Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Healthcare Foundation accessible data as well as  unauthorized read access to a subset of Oracle Healthcare Foundation accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12950V-7.1.1</ProductID>
            <ProductID>P-12950V-7.2.0</ProductID>
            <ProductID>P-12950V-7.2.1</ProductID>
            <ProductID>P-12950V-7.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-12950V-7.1.1</ProductID>
            <ProductID>P-12950V-7.2.0</ProductID>
            <ProductID>P-12950V-7.2.1</ProductID>
            <ProductID>P-12950V-7.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="132" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="132" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality Materials Control product of Oracle Food and Beverage Applications (component: Mobile Authorization (jQuery)).   The supported version that is affected is 18.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Materials Control.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Materials Control, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hospitality Materials Control accessible data as well as  unauthorized read access to a subset of Oracle Hospitality Materials Control accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12573V-18.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-12573V-18.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="133" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="133" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality Simphony product of Oracle Food and Beverage Applications (component: Simphony Apps (jQuery)).  Supported versions that are affected are 18.1, 18.2 and  19.1.0-19.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Simphony.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Simphony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hospitality Simphony accessible data as well as  unauthorized read access to a subset of Oracle Hospitality Simphony accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11594V-18.1</ProductID>
            <ProductID>P-11594V-18.2</ProductID>
            <ProductID>P-11594V-19.1.0-19.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11594V-18.1</ProductID>
            <ProductID>P-11594V-18.2</ProductID>
            <ProductID>P-11594V-19.1.0-19.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="134" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="134" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Accounting Analyzer product of Oracle Financial Services Applications (component: IFRS17 (jQuery)).   The supported version that is affected is 8.0.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Accounting Analyzer.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Insurance Accounting Analyzer, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Insurance Accounting Analyzer accessible data as well as  unauthorized read access to a subset of Oracle Insurance Accounting Analyzer accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13809V-8.0.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-13809V-8.0.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="135" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="135" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Allocation Manager for Enterprise Profitability product of Oracle Financial Services Applications (component: User Interface (jQuery)).  Supported versions that are affected are 8.0.8 and  8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Allocation Manager for Enterprise Profitability.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Insurance Allocation Manager for Enterprise Profitability, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Insurance Allocation Manager for Enterprise Profitability accessible data as well as  unauthorized read access to a subset of Oracle Insurance Allocation Manager for Enterprise Profitability accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13946V-8.0.8</ProductID>
            <ProductID>P-13946V-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-13946V-8.0.8</ProductID>
            <ProductID>P-13946V-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="136" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="136" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Data Foundation product of Oracle Financial Services Applications (component: Infrastructure (jQuery)).  Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Data Foundation.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Insurance Data Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Insurance Data Foundation accessible data as well as  unauthorized read access to a subset of Oracle Insurance Data Foundation accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9755V-8.0.6-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9755V-8.0.6-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="137" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="137" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Insbridge Rating and Underwriting product of Oracle Insurance Applications (component: Framework Administrator IBFA (jQuery)).  Supported versions that are affected are 5.0.0.0 - 5.6.0.0 and  5.6.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Insbridge Rating and Underwriting.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Insurance Insbridge Rating and Underwriting, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Insurance Insbridge Rating and Underwriting accessible data as well as  unauthorized read access to a subset of Oracle Insurance Insbridge Rating and Underwriting accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5484V-5.0.0.0 - 5.6.0.0</ProductID>
            <ProductID>P-5484V-5.6.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5484V-5.0.0.0 - 5.6.0.0</ProductID>
            <ProductID>P-5484V-5.6.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="138" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="138" Title="Details" Type="Details">Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces (jQuery)).  Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle JDeveloper, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle JDeveloper accessible data as well as  unauthorized read access to a subset of Oracle JDeveloper accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-807V-11.1.1.9.0</ProductID>
            <ProductID>P-807V-12.2.1.3.0</ProductID>
            <ProductID>P-807V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-807V-11.1.1.9.0</ProductID>
            <ProductID>P-807V-12.2.1.3.0</ProductID>
            <ProductID>P-807V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="139" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="139" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology (jQuery)).  Supported versions that are affected are 8.56, 8.57 and  8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="140" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="140" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal, Charting  (jQuery)).  Supported versions that are affected are 8.56, 8.57 and  8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="141" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="141" Title="Details" Type="Details">Vulnerability in the Oracle Policy Automation product of Oracle Policy Automation (component: Core (jQuery)).  Supported versions that are affected are 12.2.0 - 12.2.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Policy Automation.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Policy Automation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Policy Automation accessible data as well as  unauthorized read access to a subset of Oracle Policy Automation accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5624V-12.2.0 - 12.2.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5624V-12.2.0 - 12.2.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="142" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="142" Title="Details" Type="Details">Vulnerability in the Oracle Policy Automation Connector for Siebel product of Oracle Policy Automation (component: Core (jQuery)).   The supported version that is affected is 10.4.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Policy Automation Connector for Siebel.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Policy Automation Connector for Siebel, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Policy Automation Connector for Siebel accessible data as well as  unauthorized read access to a subset of Oracle Policy Automation Connector for Siebel accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5627V-10.4.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5627V-10.4.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="143" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="143" Title="Details" Type="Details">Vulnerability in the Oracle Policy Automation for Mobile Devices product of Oracle Policy Automation (component: Core (jQuery)).  Supported versions that are affected are 12.2.0 - 12.2.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Policy Automation for Mobile Devices.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Policy Automation for Mobile Devices, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Policy Automation for Mobile Devices accessible data as well as  unauthorized read access to a subset of Oracle Policy Automation for Mobile Devices accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5626V-12.2.0 - 12.2.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5626V-12.2.0 - 12.2.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="144" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="144" Title="Details" Type="Details">Vulnerability in the Oracle Retail Back Office product of Oracle Retail Applications (component: Security (jQuery)).  Supported versions that are affected are 14.0 and  14.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Back Office.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Back Office, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail Back Office accessible data as well as  unauthorized read access to a subset of Oracle Retail Back Office accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2013V-14.0</ProductID>
            <ProductID>P-2013V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2013V-14.0</ProductID>
            <ProductID>P-2013V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="145" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="145" Title="Details" Type="Details">Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Segments (jQuery)).   The supported version that is affected is 19.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Customer Management and Segmentation Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail Customer Management and Segmentation Foundation accessible data as well as  unauthorized read access to a subset of Oracle Retail Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13388V-19.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-13388V-19.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="146" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="146" Title="Details" Type="Details">Vulnerability in the Oracle Retail Returns Management product of Oracle Retail Applications (component: Security (jQuery)).  Supported versions that are affected are 14.0 and  14.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Returns Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Returns Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail Returns Management accessible data as well as  unauthorized read access to a subset of Oracle Retail Returns Management accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2020V-14.0</ProductID>
            <ProductID>P-2020V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2020V-14.0</ProductID>
            <ProductID>P-2020V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="147" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="147" Title="Details" Type="Details">Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: UIF Open UI (jQuery)).   The supported version that is affected is 20.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel UI Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel UI Framework accessible data as well as  unauthorized read access to a subset of Siebel UI Framework accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-20.8</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9011V-20.8</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="148" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11022</Title>
      <Notes>
         <Note Audience="All" Ordinal="148" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console (jQuery)).  Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data as well as  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11022</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="149" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11023</Title>
      <Notes>
         <Note Audience="All" Ordinal="149" Title="Details" Type="Details">Vulnerability in the Oracle Application Express (jQuery) component of Oracle Database Server.   The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Express (jQuery).  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express (jQuery), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Application Express (jQuery) accessible data as well as  unauthorized read access to a subset of Oracle Application Express (jQuery) accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11023</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1348V-Prior to 20.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1348V-Prior to 20.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="150" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11023</Title>
      <Notes>
         <Note Audience="All" Ordinal="150" Title="Details" Type="Details">Vulnerability in the ORDS (jQuery) component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and  19c. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise ORDS (jQuery).  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in ORDS (jQuery), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of ORDS (jQuery) accessible data as well as  unauthorized read access to a subset of ORDS (jQuery) accessible data.  Note: Additional ORDS bugs are documented in the risk matrix "Oracle REST Data Services Risk Matrix". CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11023</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-18c</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-18c</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="151" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11023</Title>
      <Notes>
         <Note Audience="All" Ordinal="151" Title="Details" Type="Details">Vulnerability in the Oracle REST Data Services product of Oracle REST Data Services (component: General (jQuery)).  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and  19c; Standalone ORDS: prior to 20.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle REST Data Services.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle REST Data Services, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle REST Data Services accessible data as well as  unauthorized read access to a subset of Oracle REST Data Services accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11023</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9456V-11.2.0.4</ProductID>
            <ProductID>P-9456V-12.1.0.2</ProductID>
            <ProductID>P-9456V-12.2.0.1</ProductID>
            <ProductID>P-9456V-18c</ProductID>
            <ProductID>P-9456V-19c; Standalone ORDS: prior to 20.2.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9456V-11.2.0.4</ProductID>
            <ProductID>P-9456V-12.1.0.2</ProductID>
            <ProductID>P-9456V-12.2.0.1</ProductID>
            <ProductID>P-9456V-18c</ProductID>
            <ProductID>P-9456V-19c; Standalone ORDS: prior to 20.2.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="152" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11023</Title>
      <Notes>
         <Note Audience="All" Ordinal="152" Title="Details" Type="Details">Security-in-Depth issue in the Oracle Spatial and Graph MapViewer (jQuery) component of Oracle Database Server.  Supported versions that are affected are 12.2.0.1, 18c and  19c. This vulnerability cannot be exploited in the context of this product.CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11023</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-619V-12.2.0.1</ProductID>
            <ProductID>P-619V-18c</ProductID>
            <ProductID>P-619V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-619V-12.2.0.1</ProductID>
            <ProductID>P-619V-18c</ProductID>
            <ProductID>P-619V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="153" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11080</Title>
      <Notes>
         <Note Audience="All" Ordinal="153" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Border Controller product of Oracle Communications (component: System (http2)).  Supported versions that are affected are 8.3 and  8.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Border Controller. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11080</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10750V-8.3</ProductID>
            <ProductID>P-10750V-8.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10750V-8.3</ProductID>
            <ProductID>P-10750V-8.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="154" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11973</Title>
      <Notes>
         <Note Audience="All" Ordinal="154" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: IDIH (Apache Camel)).  Supported versions that are affected are IDIH: 8.0.0-8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router (DSR). CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11973</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="155" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11973</Title>
      <Notes>
         <Note Audience="All" Ordinal="155" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking product of Oracle Financial Services Applications (component: Core (Apache Camel)).  Supported versions that are affected are 12.0.0 and  12.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.  Successful attacks of this vulnerability can result in takeover of Oracle FLEXCUBE Private Banking. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11973</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="156" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11984</Title>
      <Notes>
         <Note Audience="All" Ordinal="156" Title="Details" Type="Details">Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Core (Apache HTTP Server)).  Supported versions that are affected are 8.2.0-8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Element Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11984</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11052V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11052V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="157" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11984</Title>
      <Notes>
         <Note Audience="All" Ordinal="157" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: Core (Apache HTTP Server)).  Supported versions that are affected are 8.2.0-8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Report Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11984</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10770V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10770V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="158" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11984</Title>
      <Notes>
         <Note Audience="All" Ordinal="158" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Route Manager product of Oracle Communications (component: Core (Apache HTTP Server)).  Supported versions that are affected are 8.2.0-8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Route Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Route Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11984</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10771V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10771V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="159" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-11984</Title>
      <Notes>
         <Note Audience="All" Ordinal="159" Title="Details" Type="Details">Vulnerability in the Instantis EnterpriseTrack product of Oracle Construction and Engineering (component: Core (Apache HTTP Server)).  Supported versions that are affected are 17.1, 17.2 and  17.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Instantis EnterpriseTrack.  Successful attacks of this vulnerability can result in takeover of Instantis EnterpriseTrack. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-11984</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10563V-17.1</ProductID>
            <ProductID>P-10563V-17.2</ProductID>
            <ProductID>P-10563V-17.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10563V-17.1</ProductID>
            <ProductID>P-10563V-17.2</ProductID>
            <ProductID>P-10563V-17.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="160" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13631</Title>
      <Notes>
         <Note Audience="All" Ordinal="160" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Installation  (SQLite)).  Supported versions that are affected are 8.5.5 and  8.5.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Outside In Technology executes to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Outside In Technology accessible data.  Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network the CVSS score may be lower. CVSS 3.1 Base Score 5.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13631</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.5</ProductID>
            <ProductID>P-2276V-8.5.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2276V-8.5.5</ProductID>
            <ProductID>P-2276V-8.5.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="161" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13935</Title>
      <Notes>
         <Note Audience="All" Ordinal="161" Title="Details" Type="Details">Vulnerability in the Workload Manager (Apache Tomcat) component of Oracle Database Server.  Supported versions that are affected are 12.2.0.1, 18c and  19c. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Workload Manager (Apache Tomcat).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Workload Manager (Apache Tomcat). CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13935</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-18c</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-18c</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="162" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13935</Title>
      <Notes>
         <Note Audience="All" Ordinal="162" Title="Details" Type="Details">Vulnerability in the Instantis EnterpriseTrack product of Oracle Construction and Engineering (component: Core (Apache Tomcat)).  Supported versions that are affected are 17.1, 17.2 and  17.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Instantis EnterpriseTrack.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Instantis EnterpriseTrack. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13935</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10563V-17.1</ProductID>
            <ProductID>P-10563V-17.2</ProductID>
            <ProductID>P-10563V-17.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10563V-17.1</ProductID>
            <ProductID>P-10563V-17.2</ProductID>
            <ProductID>P-10563V-17.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="163" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-13935</Title>
      <Notes>
         <Note Audience="All" Ordinal="163" Title="Details" Type="Details">Vulnerability in the MySQL Enterprise Monitor product of Oracle MySQL (component: Monitoring: General (Apache Tomcat)).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise MySQL Enterprise Monitor.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Enterprise Monitor. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-13935</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8480V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8480V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="164" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14195</Title>
      <Notes>
         <Note Audience="All" Ordinal="164" Title="Details" Type="Details">Vulnerability in the Oracle Banking Digital Experience product of Oracle Financial Services Applications (component: Framework (jackson-databind)).  Supported versions that are affected are 18.1, 18.2, 18.3, 19.1, 19.2 and  20.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Banking Digital Experience.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Digital Experience. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14195</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12605V-18.1</ProductID>
            <ProductID>P-12605V-18.2</ProductID>
            <ProductID>P-12605V-18.3</ProductID>
            <ProductID>P-12605V-19.1</ProductID>
            <ProductID>P-12605V-19.2</ProductID>
            <ProductID>P-12605V-20.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-12605V-18.1</ProductID>
            <ProductID>P-12605V-18.2</ProductID>
            <ProductID>P-12605V-18.3</ProductID>
            <ProductID>P-12605V-19.1</ProductID>
            <ProductID>P-12605V-19.2</ProductID>
            <ProductID>P-12605V-20.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="165" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14195</Title>
      <Notes>
         <Note Audience="All" Ordinal="165" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: IDIH (jackson-databind)).  Supported versions that are affected are IDIH: 8.0.0-8.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router (DSR). CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14195</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="166" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14195</Title>
      <Notes>
         <Note Audience="All" Ordinal="166" Title="Details" Type="Details">Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Core (jackson-databind)).  Supported versions that are affected are 8.2.0-8.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Element Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14195</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11052V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11052V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="167" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14195</Title>
      <Notes>
         <Note Audience="All" Ordinal="167" Title="Details" Type="Details">Vulnerability in the Oracle Communications Evolved Communications Application Server product of Oracle Communications (component: Universal Data Record (jackson-databind)).   The supported version that is affected is 7.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via XCAP to compromise Oracle Communications Evolved Communications Application Server.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Evolved Communications Application Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14195</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10994V-7.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10994V-7.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="168" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14195</Title>
      <Notes>
         <Note Audience="All" Ordinal="168" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: Core (jackson-databind)).  Supported versions that are affected are 8.2.0-8.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Report Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14195</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10770V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10770V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="169" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14195</Title>
      <Notes>
         <Note Audience="All" Ordinal="169" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Route Manager product of Oracle Communications (component: Core (jackson-databind)).  Supported versions that are affected are 8.2.0-8.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Session Route Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Route Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14195</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10771V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10771V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="170" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14672</Title>
      <Notes>
         <Note Audience="All" Ordinal="170" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure).  Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and  8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14672</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.49 and prior</ProductID>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-5.6.49 and prior</ProductID>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="171" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14731</Title>
      <Notes>
         <Note Audience="All" Ordinal="171" Title="Details" Type="Details">Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Segment).  Supported versions that are affected are 18.0 and  19.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Retail Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14731</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13388V-18.0</ProductID>
            <ProductID>P-13388V-19.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-13388V-18.0</ProductID>
            <ProductID>P-13388V-19.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="172" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14732</Title>
      <Notes>
         <Note Audience="All" Ordinal="172" Title="Details" Type="Details">Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Promotions).   The supported version that is affected is 19.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Customer Management and Segmentation Foundation.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Retail Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14732</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13388V-19.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-13388V-19.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="173" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14734</Title>
      <Notes>
         <Note Audience="All" Ordinal="173" Title="Details" Type="Details">Vulnerability in the Oracle Text component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and  19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Text.  Successful attacks of this vulnerability can result in takeover of Oracle Text. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14734</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-211V-11.2.0.4</ProductID>
            <ProductID>P-211V-12.1.0.2</ProductID>
            <ProductID>P-211V-12.2.0.1</ProductID>
            <ProductID>P-211V-18c</ProductID>
            <ProductID>P-211V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-211V-11.2.0.4</ProductID>
            <ProductID>P-211V-12.1.0.2</ProductID>
            <ProductID>P-211V-12.2.0.1</ProductID>
            <ProductID>P-211V-18c</ProductID>
            <ProductID>P-211V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="174" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14735</Title>
      <Notes>
         <Note Audience="All" Ordinal="174" Title="Details" Type="Details">Vulnerability in the Scheduler component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and  19c. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Scheduler executes to compromise Scheduler.  While the vulnerability is in Scheduler, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Scheduler. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14735</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-18c</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-18c</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="175" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14736</Title>
      <Notes>
         <Note Audience="All" Ordinal="175" Title="Details" Type="Details">Vulnerability in the Database Vault component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.2 and  12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create Public Synonym privilege with network access via Oracle Net to compromise Database Vault.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Database Vault accessible data as well as  unauthorized read access to a subset of Database Vault accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14736</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.8</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="176" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14740</Title>
      <Notes>
         <Note Audience="All" Ordinal="176" Title="Details" Type="Details">Vulnerability in the SQL Developer Install component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and  18c. Easily exploitable vulnerability allows low privileged attacker having Client Computer User Account privilege with logon to the infrastructure where SQL Developer Install executes to compromise SQL Developer Install.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of SQL Developer Install accessible data. CVSS 3.1 Base Score 2.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14740</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1875V-11.2.0.4</ProductID>
            <ProductID>P-1875V-12.1.0.2</ProductID>
            <ProductID>P-1875V-12.2.0.1</ProductID>
            <ProductID>P-1875V-18c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1875V-11.2.0.4</ProductID>
            <ProductID>P-1875V-12.1.0.2</ProductID>
            <ProductID>P-1875V-12.2.0.1</ProductID>
            <ProductID>P-1875V-18c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="177" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14741</Title>
      <Notes>
         <Note Audience="All" Ordinal="177" Title="Details" Type="Details">Vulnerability in the Database Filesystem component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.2 and  12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Resource, Create Table, Create View, Create
Procedure, Dbfs_role privilege with network access via Oracle Net to compromise Database Filesystem.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Database Filesystem. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14741</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="178" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14742</Title>
      <Notes>
         <Note Audience="All" Ordinal="178" Title="Details" Type="Details">Vulnerability in the Core RDBMS component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and  19c. Easily exploitable vulnerability allows high privileged attacker having SYSDBA level account privilege with network access via Oracle Net to compromise Core RDBMS.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Core RDBMS accessible data. CVSS 3.1 Base Score 2.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14742</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-18c</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.7</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-18c</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="179" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14743</Title>
      <Notes>
         <Note Audience="All" Ordinal="179" Title="Details" Type="Details">Vulnerability in the Java VM component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and  19c. Difficult to exploit vulnerability allows low privileged attacker having Create Procedure privilege with network access via multiple protocols to compromise Java VM.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Java VM accessible data. CVSS 3.1 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14743</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-18c</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
            <ProductID>P-5V-12.2.0.1</ProductID>
            <ProductID>P-5V-18c</ProductID>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="180" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14744</Title>
      <Notes>
         <Note Audience="All" Ordinal="180" Title="Details" Type="Details">Vulnerability in the Oracle REST Data Services product of Oracle REST Data Services (component: General).  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and  19c; Standalone ORDS: prior to 20.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle REST Data Services.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle REST Data Services accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14744</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9456V-11.2.0.4</ProductID>
            <ProductID>P-9456V-12.1.0.2</ProductID>
            <ProductID>P-9456V-12.2.0.1</ProductID>
            <ProductID>P-9456V-18c</ProductID>
            <ProductID>P-9456V-19c; Standalone ORDS: prior to 20.2.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9456V-11.2.0.4</ProductID>
            <ProductID>P-9456V-12.1.0.2</ProductID>
            <ProductID>P-9456V-12.2.0.1</ProductID>
            <ProductID>P-9456V-18c</ProductID>
            <ProductID>P-9456V-19c; Standalone ORDS: prior to 20.2.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="181" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14745</Title>
      <Notes>
         <Note Audience="All" Ordinal="181" Title="Details" Type="Details">Vulnerability in the Oracle REST Data Services product of Oracle REST Data Services (component: General).  Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and  19c; Standalone ORDS: prior to 20.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle REST Data Services.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle REST Data Services accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14745</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9456V-11.2.0.4</ProductID>
            <ProductID>P-9456V-12.1.0.2</ProductID>
            <ProductID>P-9456V-12.2.0.1</ProductID>
            <ProductID>P-9456V-18c</ProductID>
            <ProductID>P-9456V-19c; Standalone ORDS: prior to 20.2.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9456V-11.2.0.4</ProductID>
            <ProductID>P-9456V-12.1.0.2</ProductID>
            <ProductID>P-9456V-12.2.0.1</ProductID>
            <ProductID>P-9456V-18c</ProductID>
            <ProductID>P-9456V-19c; Standalone ORDS: prior to 20.2.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="182" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14746</Title>
      <Notes>
         <Note Audience="All" Ordinal="182" Title="Details" Type="Details">Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Popup windows).  Supported versions that are affected are 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 4.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14746</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1472V-12.1.3</ProductID>
            <ProductID>P-1472V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1472V-12.1.3</ProductID>
            <ProductID>P-1472V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="183" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14752</Title>
      <Notes>
         <Note Audience="All" Ordinal="183" Title="Details" Type="Details">Vulnerability in the Hyperion Lifecycle Management product of Oracle Hyperion (component: Shared Services).   The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Lifecycle Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Hyperion Lifecycle Management accessible data. CVSS 3.1 Base Score 4.2 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14752</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4482V-11.1.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.2</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4482V-11.1.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="184" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14753</Title>
      <Notes>
         <Note Audience="All" Ordinal="184" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality Reporting and Analytics product of Oracle Food and Beverage Applications (component: Installation).   The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Reporting and Analytics executes to compromise Oracle Hospitality Reporting and Analytics.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality Reporting and Analytics, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hospitality Reporting and Analytics accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14753</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11599V-9.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11599V-9.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="185" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14754</Title>
      <Notes>
         <Note Audience="All" Ordinal="185" Title="Details" Type="Details">Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem).   The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14754</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="186" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14757</Title>
      <Notes>
         <Note Audience="All" Ordinal="186" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services).   The supported version that is affected is 12.2.1.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14757</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="187" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14758</Title>
      <Notes>
         <Note Audience="All" Ordinal="187" Title="Details" Type="Details">Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel).   The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Solaris accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.6 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14758</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.6</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="188" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14759</Title>
      <Notes>
         <Note Audience="All" Ordinal="188" Title="Details" Type="Details">Vulnerability in the Oracle Solaris product of Oracle Systems (component: Kernel).   The supported version that is affected is 11. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Solaris accessible data. CVSS 3.1 Base Score 2.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14759</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.5</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="189" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14760</Title>
      <Notes>
         <Note Audience="All" Ordinal="189" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 5.7.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14760</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="190" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14761</Title>
      <Notes>
         <Note Audience="All" Ordinal="190" Title="Details" Type="Details">Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces).  Supported versions that are affected are 12.1.3 and  12.2.3 - 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Applications Manager accessible data as well as  unauthorized read access to a subset of Oracle Applications Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14761</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-99V-12.1.3</ProductID>
            <ProductID>P-99V-12.2.3 - 12.2.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-99V-12.1.3</ProductID>
            <ProductID>P-99V-12.2.3 - 12.2.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="191" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14762</Title>
      <Notes>
         <Note Audience="All" Ordinal="191" Title="Details" Type="Details">Vulnerability in the Oracle Application Express component of Oracle Database Server.   The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as  unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14762</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1348V-Prior to 20.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1348V-Prior to 20.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="192" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14763</Title>
      <Notes>
         <Note Audience="All" Ordinal="192" Title="Details" Type="Details">Vulnerability in the Oracle Application Express Quick Poll component of Oracle Database Server.   The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Quick Poll.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express Quick Poll, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Application Express Quick Poll accessible data as well as  unauthorized read access to a subset of Oracle Application Express Quick Poll accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14763</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1348V-Prior to 20.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1348V-Prior to 20.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="193" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14764</Title>
      <Notes>
         <Note Audience="All" Ordinal="193" Title="Details" Type="Details">Vulnerability in the Hyperion Planning product of Oracle Hyperion (component: Application Development Framework).   The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Planning.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Hyperion Planning accessible data. CVSS 3.1 Base Score 4.2 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14764</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4402V-11.1.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.2</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4402V-11.1.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="194" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14765</Title>
      <Notes>
         <Note Audience="All" Ordinal="194" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS).  Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and  8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14765</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.49 and prior</ProductID>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-5.6.49 and prior</ProductID>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="195" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14766</Title>
      <Notes>
         <Note Audience="All" Ordinal="195" Title="Details" Type="Details">Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Web Administration).  Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14766</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2025V-5.5.0.0.0</ProductID>
            <ProductID>P-2025V-11.1.1.9.0</ProductID>
            <ProductID>P-2025V-12.2.1.3.0</ProductID>
            <ProductID>P-2025V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2025V-5.5.0.0.0</ProductID>
            <ProductID>P-2025V-11.1.1.9.0</ProductID>
            <ProductID>P-2025V-12.2.1.3.0</ProductID>
            <ProductID>P-2025V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="196" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14767</Title>
      <Notes>
         <Note Audience="All" Ordinal="196" Title="Details" Type="Details">Vulnerability in the Hyperion BI+ product of Oracle Hyperion (component: IQR-Foundation service).   The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise Hyperion BI+.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Hyperion BI+ accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14767</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4361V-11.1.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.2</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4361V-11.1.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="197" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14768</Title>
      <Notes>
         <Note Audience="All" Ordinal="197" Title="Details" Type="Details">Vulnerability in the Hyperion Analytic Provider Services product of Oracle Hyperion (component: Smart View Provider).   The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Hyperion Analytic Provider Services executes to compromise Hyperion Analytic Provider Services.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Hyperion Analytic Provider Services accessible data as well as  unauthorized read access to a subset of Hyperion Analytic Provider Services accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Hyperion Analytic Provider Services. CVSS 3.1 Base Score 4.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14768</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4349V-11.1.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:A/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4349V-11.1.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="198" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14769</Title>
      <Notes>
         <Note Audience="All" Ordinal="198" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and  8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14769</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.49 and prior</ProductID>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-5.6.49 and prior</ProductID>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="199" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14770</Title>
      <Notes>
         <Note Audience="All" Ordinal="199" Title="Details" Type="Details">Vulnerability in the Hyperion BI+ product of Oracle Hyperion (component: IQR-Foundation service).   The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise Hyperion BI+.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Hyperion BI+ accessible data. CVSS 3.1 Base Score 2.0 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14770</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4361V-11.1.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.0</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4361V-11.1.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="200" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14771</Title>
      <Notes>
         <Note Audience="All" Ordinal="200" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth).  Supported versions that are affected are 5.7.31 and prior and  8.0.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14771</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.2</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="201" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14772</Title>
      <Notes>
         <Note Audience="All" Ordinal="201" Title="Details" Type="Details">Vulnerability in the Hyperion Lifecycle Management product of Oracle Hyperion (component: Shared Services).   The supported version that is affected is 11.1.2.4. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Lifecycle Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Hyperion Lifecycle Management accessible data. CVSS 3.1 Base Score 4.2 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14772</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4482V-11.1.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.2</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4482V-11.1.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="202" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14773</Title>
      <Notes>
         <Note Audience="All" Ordinal="202" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14773</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="203" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14774</Title>
      <Notes>
         <Note Audience="All" Ordinal="203" Title="Details" Type="Details">Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences).  Supported versions that are affected are 12.1.1 - 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle CRM Technical Foundation. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14774</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1199V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-1199V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1199V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-1199V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="204" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14775</Title>
      <Notes>
         <Note Audience="All" Ordinal="204" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 5.7.31 and prior and  8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14775</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="205" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14776</Title>
      <Notes>
         <Note Audience="All" Ordinal="205" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 5.7.31 and prior and  8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14776</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="206" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14777</Title>
      <Notes>
         <Note Audience="All" Ordinal="206" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14777</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="207" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14778</Title>
      <Notes>
         <Note Audience="All" Ordinal="207" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise HCM Global Payroll Core product of Oracle PeopleSoft (component: Security).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Global Payroll Core.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise HCM Global Payroll Core accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise HCM Global Payroll Core accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise HCM Global Payroll Core. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14778</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5055V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5055V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="208" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14779</Title>
      <Notes>
         <Note Audience="All" Ordinal="208" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization).  Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and  15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded.  Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14779</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 7u271</ProductID>
            <ProductID>P-856V-8u261</ProductID>
            <ProductID>P-856V-11.0.8</ProductID>
            <ProductID>P-856V-15; Java SE Embedded: 8u261</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-856V-Java SE: 7u271</ProductID>
            <ProductID>P-856V-8u261</ProductID>
            <ProductID>P-856V-11.0.8</ProductID>
            <ProductID>P-856V-15; Java SE Embedded: 8u261</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="209" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14780</Title>
      <Notes>
         <Note Audience="All" Ordinal="209" Title="Details" Type="Details">Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security).  Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all BI Publisher accessible data as well as  unauthorized update, insert or delete access to some of BI Publisher accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14780</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="210" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14781</Title>
      <Notes>
         <Note Audience="All" Ordinal="210" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JNDI).  Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and  15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Java SE, Java SE Embedded accessible data.  Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14781</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 7u271</ProductID>
            <ProductID>P-856V-8u261</ProductID>
            <ProductID>P-856V-11.0.8</ProductID>
            <ProductID>P-856V-15; Java SE Embedded: 8u261</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-856V-Java SE: 7u271</ProductID>
            <ProductID>P-856V-8u261</ProductID>
            <ProductID>P-856V-11.0.8</ProductID>
            <ProductID>P-856V-15; Java SE Embedded: 8u261</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="211" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14782</Title>
      <Notes>
         <Note Audience="All" Ordinal="211" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and  15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data.  Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14782</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 7u271</ProductID>
            <ProductID>P-856V-8u261</ProductID>
            <ProductID>P-856V-11.0.8</ProductID>
            <ProductID>P-856V-15; Java SE Embedded: 8u261</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-856V-Java SE: 7u271</ProductID>
            <ProductID>P-856V-8u261</ProductID>
            <ProductID>P-856V-11.0.8</ProductID>
            <ProductID>P-856V-15; Java SE Embedded: 8u261</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="212" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14783</Title>
      <Notes>
         <Note Audience="All" Ordinal="212" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality RES 3700 product of Oracle Food and Beverage Applications (component: CAL).   The supported version that is affected is 5.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hospitality RES 3700.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hospitality RES 3700 accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14783</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11596V-5.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11596V-5.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="213" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14784</Title>
      <Notes>
         <Note Audience="All" Ordinal="213" Title="Details" Type="Details">Vulnerability in the Oracle BI Publisher product of Oracle Fusion Middleware (component: Mobile Service).  Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as  unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14784</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="214" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14785</Title>
      <Notes>
         <Note Audience="All" Ordinal="214" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14785</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="215" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14786</Title>
      <Notes>
         <Note Audience="All" Ordinal="215" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14786</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="216" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14787</Title>
      <Notes>
         <Note Audience="All" Ordinal="216" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: User Interface).  Supported versions that are affected are 8.0.0.0-8.4.0.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Diameter Signaling Router (DSR), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Diameter Signaling Router (DSR) accessible data as well as  unauthorized read access to a subset of Oracle Communications Diameter Signaling Router (DSR) accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14787</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-8.0.0.0-8.4.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10899V-8.0.0.0-8.4.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="217" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14788</Title>
      <Notes>
         <Note Audience="All" Ordinal="217" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: User Interface).  Supported versions that are affected are 8.0.0.0-8.4.0.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Diameter Signaling Router (DSR), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Diameter Signaling Router (DSR) accessible data as well as  unauthorized read access to a subset of Oracle Communications Diameter Signaling Router (DSR) accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14788</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-8.0.0.0-8.4.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10899V-8.0.0.0-8.4.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="218" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14789</Title>
      <Notes>
         <Note Audience="All" Ordinal="218" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS).  Supported versions that are affected are 5.7.31 and prior and  8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14789</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="219" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14790</Title>
      <Notes>
         <Note Audience="All" Ordinal="219" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS).  Supported versions that are affected are 5.7.31 and prior and  8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14790</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="220" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14791</Title>
      <Notes>
         <Note Audience="All" Ordinal="220" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14791</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.2</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="221" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14792</Title>
      <Notes>
         <Note Audience="All" Ordinal="221" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Hotspot).  Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and  15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data as well as  unauthorized read access to a subset of Java SE, Java SE Embedded accessible data.  Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14792</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 7u271</ProductID>
            <ProductID>P-856V-8u261</ProductID>
            <ProductID>P-856V-11.0.8</ProductID>
            <ProductID>P-856V-15; Java SE Embedded: 8u261</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.2</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-856V-Java SE: 7u271</ProductID>
            <ProductID>P-856V-8u261</ProductID>
            <ProductID>P-856V-11.0.8</ProductID>
            <ProductID>P-856V-15; Java SE Embedded: 8u261</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="222" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14793</Title>
      <Notes>
         <Note Audience="All" Ordinal="222" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and  8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14793</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.49 and prior</ProductID>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-5.6.49 and prior</ProductID>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="223" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14794</Title>
      <Notes>
         <Note Audience="All" Ordinal="223" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14794</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="224" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14795</Title>
      <Notes>
         <Note Audience="All" Ordinal="224" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology).  Supported versions that are affected are 8.57 and  8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14795</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="225" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14796</Title>
      <Notes>
         <Note Audience="All" Ordinal="225" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and  15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Java SE, Java SE Embedded accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14796</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 7u271</ProductID>
            <ProductID>P-856V-8u261</ProductID>
            <ProductID>P-856V-11.0.8</ProductID>
            <ProductID>P-856V-15; Java SE Embedded: 8u261</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-856V-Java SE: 7u271</ProductID>
            <ProductID>P-856V-8u261</ProductID>
            <ProductID>P-856V-11.0.8</ProductID>
            <ProductID>P-856V-15; Java SE Embedded: 8u261</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="226" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14797</Title>
      <Notes>
         <Note Audience="All" Ordinal="226" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and  15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data.  Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.1 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14797</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 7u271</ProductID>
            <ProductID>P-856V-8u261</ProductID>
            <ProductID>P-856V-11.0.8</ProductID>
            <ProductID>P-856V-15; Java SE Embedded: 8u261</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-856V-Java SE: 7u271</ProductID>
            <ProductID>P-856V-8u261</ProductID>
            <ProductID>P-856V-11.0.8</ProductID>
            <ProductID>P-856V-15; Java SE Embedded: 8u261</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="227" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14798</Title>
      <Notes>
         <Note Audience="All" Ordinal="227" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and  15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14798</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 7u271</ProductID>
            <ProductID>P-856V-8u261</ProductID>
            <ProductID>P-856V-11.0.8</ProductID>
            <ProductID>P-856V-15; Java SE Embedded: 8u261</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-856V-Java SE: 7u271</ProductID>
            <ProductID>P-856V-8u261</ProductID>
            <ProductID>P-856V-11.0.8</ProductID>
            <ProductID>P-856V-15; Java SE Embedded: 8u261</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="228" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14799</Title>
      <Notes>
         <Note Audience="All" Ordinal="228" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption).  Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14799</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.20 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.20 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="229" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14800</Title>
      <Notes>
         <Note Audience="All" Ordinal="229" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14800</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="230" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14801</Title>
      <Notes>
         <Note Audience="All" Ordinal="230" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology).  Supported versions that are affected are 8.56, 8.57 and  8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14801</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="231" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14802</Title>
      <Notes>
         <Note Audience="All" Ordinal="231" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Core Technology).  Supported versions that are affected are 8.56, 8.57 and  8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14802</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="232" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14803</Title>
      <Notes>
         <Note Audience="All" Ordinal="232" Title="Details" Type="Details">Vulnerability in the Oracle GraalVM Enterprise Edition product of Oracle GraalVM (component: Java).  Supported versions that are affected are 19.3.3 and  20.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GraalVM Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle GraalVM Enterprise Edition accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14803</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13497V-19.3.3</ProductID>
            <ProductID>P-13497V-20.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-13497V-19.3.3</ProductID>
            <ProductID>P-13497V-20.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="233" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14803</Title>
      <Notes>
         <Note Audience="All" Ordinal="233" Title="Details" Type="Details">Vulnerability in the Java SE product of Oracle Java SE (component: Libraries).  Supported versions that are affected are Java SE: 11.0.8 and  15. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Java SE accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14803</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 11.0.8</ProductID>
            <ProductID>P-856V-15</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-856V-Java SE: 11.0.8</ProductID>
            <ProductID>P-856V-15</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="234" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14804</Title>
      <Notes>
         <Note Audience="All" Ordinal="234" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: FTS).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14804</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="235" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14805</Title>
      <Notes>
         <Note Audience="All" Ordinal="235" Title="Details" Type="Details">Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine).  Supported versions that are affected are 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Suite Secure Enterprise Search.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle E-Business Suite Secure Enterprise Search accessible data as well as  unauthorized access to critical data or complete access to all Oracle E-Business Suite Secure Enterprise Search accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14805</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4574V-12.1.3</ProductID>
            <ProductID>P-4574V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4574V-12.1.3</ProductID>
            <ProductID>P-4574V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="236" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14806</Title>
      <Notes>
         <Note Audience="All" Ordinal="236" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query).  Supported versions that are affected are 8.56, 8.57 and  8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14806</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="237" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14807</Title>
      <Notes>
         <Note Audience="All" Ordinal="237" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality Suite8 product of Oracle Hospitality Applications (component: WebConnect).  Supported versions that are affected are 8.10.2 and  8.11-8.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Suite8.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hospitality Suite8 accessible data as well as  unauthorized update, insert or delete access to some of Oracle Hospitality Suite8 accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14807</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12619V-8.10.2</ProductID>
            <ProductID>P-12619V-8.11-8.14</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-12619V-8.10.2</ProductID>
            <ProductID>P-12619V-8.11-8.14</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="238" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14808</Title>
      <Notes>
         <Note Audience="All" Ordinal="238" Title="Details" Type="Details">Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: User Interface).  Supported versions that are affected are 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Trade Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Trade Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Trade Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14808</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-765V-12.1.3</ProductID>
            <ProductID>P-765V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-765V-12.1.3</ProductID>
            <ProductID>P-765V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="239" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14809</Title>
      <Notes>
         <Note Audience="All" Ordinal="239" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14809</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="240" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14810</Title>
      <Notes>
         <Note Audience="All" Ordinal="240" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality Suite8 product of Oracle Hospitality Applications (component: WebConnect).  Supported versions that are affected are 8.10.2 and  8.11-8.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality Suite8.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hospitality Suite8 accessible data as well as  unauthorized read access to a subset of Oracle Hospitality Suite8 accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14810</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12619V-8.10.2</ProductID>
            <ProductID>P-12619V-8.11-8.14</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-12619V-8.10.2</ProductID>
            <ProductID>P-12619V-8.11-8.14</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="241" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14811</Title>
      <Notes>
         <Note Audience="All" Ordinal="241" Title="Details" Type="Details">Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: AMP EBS Integration).  Supported versions that are affected are 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Applications Manager accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14811</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-99V-12.1.3</ProductID>
            <ProductID>P-99V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-99V-12.1.3</ProductID>
            <ProductID>P-99V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="242" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14812</Title>
      <Notes>
         <Note Audience="All" Ordinal="242" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Locking).  Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and  8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14812</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.49 and prior</ProductID>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-5.6.49 and prior</ProductID>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="243" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14813</Title>
      <Notes>
         <Note Audience="All" Ordinal="243" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: PIA Grids).  Supported versions that are affected are 8.56, 8.57 and  8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14813</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="244" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14814</Title>
      <Notes>
         <Note Audience="All" Ordinal="244" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14814</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="245" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14815</Title>
      <Notes>
         <Note Audience="All" Ordinal="245" Title="Details" Type="Details">Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions).  Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14815</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2025V-5.5.0.0.0</ProductID>
            <ProductID>P-2025V-12.2.1.3.0</ProductID>
            <ProductID>P-2025V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2025V-5.5.0.0.0</ProductID>
            <ProductID>P-2025V-12.2.1.3.0</ProductID>
            <ProductID>P-2025V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="246" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14816</Title>
      <Notes>
         <Note Audience="All" Ordinal="246" Title="Details" Type="Details">Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration).  Supported versions that are affected are 12.1.1 - 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as  unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14816</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-229V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-229V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-229V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-229V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="247" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14817</Title>
      <Notes>
         <Note Audience="All" Ordinal="247" Title="Details" Type="Details">Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration).  Supported versions that are affected are 12.1.1 - 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as  unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14817</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-229V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-229V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-229V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-229V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="248" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14818</Title>
      <Notes>
         <Note Audience="All" Ordinal="248" Title="Details" Type="Details">Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility).   The supported version that is affected is 11. Difficult to exploit vulnerability allows low privileged attacker with network access via SSH to compromise Oracle Solaris.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Solaris accessible data. CVSS 3.1 Base Score 3.0 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14818</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.0</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="249" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14819</Title>
      <Notes>
         <Note Audience="All" Ordinal="249" Title="Details" Type="Details">Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Print Server).   The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data as well as  unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14819</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1379V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1379V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="250" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14820</Title>
      <Notes>
         <Note Audience="All" Ordinal="250" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14820</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="251" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14821</Title>
      <Notes>
         <Note Audience="All" Ordinal="251" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14821</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="252" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14822</Title>
      <Notes>
         <Note Audience="All" Ordinal="252" Title="Details" Type="Details">Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: APIs).  Supported versions that are affected are 12.1.1 - 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Installed Base, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Installed Base accessible data. CVSS 3.1 Base Score 4.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14822</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1118V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-1118V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1118V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-1118V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="253" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14823</Title>
      <Notes>
         <Note Audience="All" Ordinal="253" Title="Details" Type="Details">Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences).  Supported versions that are affected are 12.2.3 - 12.2.10. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle CRM Technical Foundation.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle CRM Technical Foundation accessible data as well as  unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14823</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1199V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1199V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="254" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14824</Title>
      <Notes>
         <Note Audience="All" Ordinal="254" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure).  Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  While the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 8.6 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14824</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5680V-8.0.6-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5680V-8.0.6-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="255" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14825</Title>
      <Notes>
         <Note Audience="All" Ordinal="255" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14825</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="256" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14826</Title>
      <Notes>
         <Note Audience="All" Ordinal="256" Title="Details" Type="Details">Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: SQL Extensions).  Supported versions that are affected are 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Applications Manager accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14826</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-99V-12.1.3</ProductID>
            <ProductID>P-99V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-99V-12.1.3</ProductID>
            <ProductID>P-99V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="257" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14827</Title>
      <Notes>
         <Note Audience="All" Ordinal="257" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth).  Supported versions that are affected are 5.7.31 and prior and  8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14827</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="258" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14828</Title>
      <Notes>
         <Note Audience="All" Ordinal="258" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14828</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.2</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="259" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14829</Title>
      <Notes>
         <Note Audience="All" Ordinal="259" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14829</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="260" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14830</Title>
      <Notes>
         <Note Audience="All" Ordinal="260" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14830</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="261" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14831</Title>
      <Notes>
         <Note Audience="All" Ordinal="261" Title="Details" Type="Details">Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration).  Supported versions that are affected are 12.1.1 - 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as  unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14831</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-229V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-229V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-229V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-229V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="262" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14832</Title>
      <Notes>
         <Note Audience="All" Ordinal="262" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker).  Supported versions that are affected are 8.56, 8.57 and  8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14832</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="263" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14833</Title>
      <Notes>
         <Note Audience="All" Ordinal="263" Title="Details" Type="Details">Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: User Interface).  Supported versions that are affected are 12.1.1 - 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Trade Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Trade Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Trade Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14833</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-765V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-765V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-765V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-765V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="264" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14834</Title>
      <Notes>
         <Note Audience="All" Ordinal="264" Title="Details" Type="Details">Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: User Interface).  Supported versions that are affected are 12.1.1 - 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Trade Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Trade Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Trade Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14834</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-765V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-765V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-765V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-765V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="265" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14835</Title>
      <Notes>
         <Note Audience="All" Ordinal="265" Title="Details" Type="Details">Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration).  Supported versions that are affected are 12.1.1 - 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as  unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14835</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-229V-12.1.1 - 12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-229V-12.1.1 - 12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="266" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14836</Title>
      <Notes>
         <Note Audience="All" Ordinal="266" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14836</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="267" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14837</Title>
      <Notes>
         <Note Audience="All" Ordinal="267" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14837</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="268" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14838</Title>
      <Notes>
         <Note Audience="All" Ordinal="268" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14838</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="269" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14839</Title>
      <Notes>
         <Note Audience="All" Ordinal="269" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14839</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="270" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14840</Title>
      <Notes>
         <Note Audience="All" Ordinal="270" Title="Details" Type="Details">Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Diagnostics).  Supported versions that are affected are 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Application Object Library accessible data. CVSS 3.1 Base Score 4.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14840</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-510V-12.1.3</ProductID>
            <ProductID>P-510V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-510V-12.1.3</ProductID>
            <ProductID>P-510V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="271" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14841</Title>
      <Notes>
         <Note Audience="All" Ordinal="271" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14841</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="272" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14842</Title>
      <Notes>
         <Note Audience="All" Ordinal="272" Title="Details" Type="Details">Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: BI Publisher Security).  Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise BI Publisher.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all BI Publisher accessible data as well as  unauthorized update, insert or delete access to some of BI Publisher accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14842</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="273" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14843</Title>
      <Notes>
         <Note Audience="All" Ordinal="273" Title="Details" Type="Details">Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Analytics Actions).  Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14843</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2025V-5.5.0.0.0</ProductID>
            <ProductID>P-2025V-12.2.1.3.0</ProductID>
            <ProductID>P-2025V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2025V-5.5.0.0.0</ProductID>
            <ProductID>P-2025V-12.2.1.3.0</ProductID>
            <ProductID>P-2025V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="274" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14844</Title>
      <Notes>
         <Note Audience="All" Ordinal="274" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14844</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="275" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14845</Title>
      <Notes>
         <Note Audience="All" Ordinal="275" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14845</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="276" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14846</Title>
      <Notes>
         <Note Audience="All" Ordinal="276" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14846</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="277" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14847</Title>
      <Notes>
         <Note Audience="All" Ordinal="277" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Query).  Supported versions that are affected are 8.56, 8.57 and  8.58. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14847</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.7</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="278" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14848</Title>
      <Notes>
         <Note Audience="All" Ordinal="278" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14848</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="279" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14849</Title>
      <Notes>
         <Note Audience="All" Ordinal="279" Title="Details" Type="Details">Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration).  Supported versions that are affected are 12.1.1 - 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as  unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14849</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-229V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-229V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-229V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-229V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="280" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14850</Title>
      <Notes>
         <Note Audience="All" Ordinal="280" Title="Details" Type="Details">Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Flex Fields).  Supported versions that are affected are 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as  unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14850</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1199V-12.1.3</ProductID>
            <ProductID>P-1199V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1199V-12.1.3</ProductID>
            <ProductID>P-1199V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="281" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14851</Title>
      <Notes>
         <Note Audience="All" Ordinal="281" Title="Details" Type="Details">Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: User Interface).  Supported versions that are affected are 12.1.1 - 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Trade Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Trade Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Trade Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14851</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-765V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-765V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-765V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-765V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="282" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14852</Title>
      <Notes>
         <Note Audience="All" Ordinal="282" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Charsets).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14852</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="283" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14853</Title>
      <Notes>
         <Note Audience="All" Ordinal="283" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.1 Base Score 4.6 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14853</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.6</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8479V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="284" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14854</Title>
      <Notes>
         <Note Audience="All" Ordinal="284" Title="Details" Type="Details">Vulnerability in the Hyperion Infrastructure Technology product of Oracle Hyperion (component: UI and Visualization).   The supported version that is affected is 11.1.2.4. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Hyperion Infrastructure Technology.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Hyperion Infrastructure Technology accessible data as well as  unauthorized access to critical data or complete access to all Hyperion Infrastructure Technology accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14854</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4392V-11.1.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4392V-11.1.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="285" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14855</Title>
      <Notes>
         <Note Audience="All" Ordinal="285" Title="Details" Type="Details">Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Work Provider Administration).   The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Universal Work Queue.  Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14855</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-778V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-778V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="286" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14856</Title>
      <Notes>
         <Note Audience="All" Ordinal="286" Title="Details" Type="Details">Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: User Interface).  Supported versions that are affected are 12.1.1 - 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Trade Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Trade Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Trade Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14856</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-765V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-765V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-765V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-765V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="287" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14857</Title>
      <Notes>
         <Note Audience="All" Ordinal="287" Title="Details" Type="Details">Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: User Interface).  Supported versions that are affected are 12.1.1 - 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Trade Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Trade Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Trade Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14857</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-765V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-765V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-765V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-765V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="288" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14858</Title>
      <Notes>
         <Note Audience="All" Ordinal="288" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Logging).  Supported versions that are affected are 5.5 and  5.6. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Hospitality OPERA 5 Property Services. CVSS 3.1 Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14858</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11580V-5.5</ProductID>
            <ProductID>P-11580V-5.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.8</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11580V-5.5</ProductID>
            <ProductID>P-11580V-5.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="289" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14859</Title>
      <Notes>
         <Note Audience="All" Ordinal="289" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via IIOP, T3 to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14859</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="290" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14860</Title>
      <Notes>
         <Note Audience="All" Ordinal="290" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Roles).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 2.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14860</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.7</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="291" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14861</Title>
      <Notes>
         <Note Audience="All" Ordinal="291" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14861</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="292" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14862</Title>
      <Notes>
         <Note Audience="All" Ordinal="292" Title="Details" Type="Details">Vulnerability in the Oracle Universal Work Queue product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3 - 12.2.9. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Universal Work Queue.  Successful attacks of this vulnerability can result in takeover of Oracle Universal Work Queue. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14862</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-778V-12.2.3 - 12.2.9</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-778V-12.2.3 - 12.2.9</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="293" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14863</Title>
      <Notes>
         <Note Audience="All" Ordinal="293" Title="Details" Type="Details">Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Print Server).  Supported versions that are affected are 12.1.1 - 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data as well as  unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14863</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1379V-12.1.1 - 12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1379V-12.1.1 - 12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="294" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14864</Title>
      <Notes>
         <Note Audience="All" Ordinal="294" Title="Details" Type="Details">Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Fusion Middleware (component: Installation).  Supported versions that are affected are 5.5.0.0.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14864</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2025V-5.5.0.0.0</ProductID>
            <ProductID>P-2025V-12.2.1.3.0</ProductID>
            <ProductID>P-2025V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2025V-5.5.0.0.0</ProductID>
            <ProductID>P-2025V-12.2.1.3.0</ProductID>
            <ProductID>P-2025V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="295" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14865</Title>
      <Notes>
         <Note Audience="All" Ordinal="295" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise SCM eSupplier Connection product of Oracle PeopleSoft (component: eSupplier Connection).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM eSupplier Connection.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM eSupplier Connection accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM eSupplier Connection accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14865</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5122V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5122V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="296" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14866</Title>
      <Notes>
         <Note Audience="All" Ordinal="296" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14866</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="297" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14867</Title>
      <Notes>
         <Note Audience="All" Ordinal="297" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL).  Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and  8.0.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14867</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.49 and prior</ProductID>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.4</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-5.6.49 and prior</ProductID>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="298" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14868</Title>
      <Notes>
         <Note Audience="All" Ordinal="298" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14868</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="299" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14869</Title>
      <Notes>
         <Note Audience="All" Ordinal="299" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth).  Supported versions that are affected are 5.7.31 and prior and  8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14869</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-5.7.31 and prior</ProductID>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="300" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14870</Title>
      <Notes>
         <Note Audience="All" Ordinal="300" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: X Plugin).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14870</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="301" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14871</Title>
      <Notes>
         <Note Audience="All" Ordinal="301" Title="Details" Type="Details">Vulnerability in the Oracle Solaris product of Oracle Systems (component: Pluggable authentication module).  Supported versions that are affected are 10 and  11. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Solaris.  While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Solaris.  Note: This CVE is not exploitable for Solaris 11.1 and later releases, and ZFSSA 8.7 and later releases, thus the CVSS Base Score is 0.0. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14871</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="302" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14871</Title>
      <Notes>
         <Note Audience="All" Ordinal="302" Title="Details" Type="Details">Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Operating System Image).   The supported version that is affected is 8.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle ZFS Storage Appliance Kit.  While the vulnerability is in Oracle ZFS Storage Appliance Kit, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle ZFS Storage Appliance Kit.  Note: This CVE is not exploitable for Solaris 11.1 and later releases, and ZFSSA 8.7 and later releases, thus the CVSS Base Score is 0.0. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14871</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10026V-8.8</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10026V-8.8</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="303" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14872</Title>
      <Notes>
         <Note Audience="All" Ordinal="303" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is Prior to 6.1.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14872</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 6.1.16</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8370V-Prior to 6.1.16</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="304" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14873</Title>
      <Notes>
         <Note Audience="All" Ordinal="304" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Logging).  Supported versions that are affected are 8.0.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14873</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.4</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="305" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14875</Title>
      <Notes>
         <Note Audience="All" Ordinal="305" Title="Details" Type="Details">Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Marketing Administration).  Supported versions that are affected are 12.1.1 - 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Marketing accessible data as well as  unauthorized access to critical data or complete access to all Oracle Marketing accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14875</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-229V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-229V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-229V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-229V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="306" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14876</Title>
      <Notes>
         <Note Audience="All" Ordinal="306" Title="Details" Type="Details">Vulnerability in the Oracle Trade Management product of Oracle E-Business Suite (component: User Interface).  Supported versions that are affected are 12.1.1 - 12.1.3 and  12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Trade Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Trade Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Trade Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14876</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-765V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-765V-12.2.3 - 12.2.10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-765V-12.1.1 - 12.1.3</ProductID>
            <ProductID>P-765V-12.2.3 - 12.2.10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="307" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14877</Title>
      <Notes>
         <Note Audience="All" Ordinal="307" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Logging).  Supported versions that are affected are 5.5 and  5.6. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality OPERA 5 Property Services accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hospitality OPERA 5 Property Services accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14877</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11580V-5.5</ProductID>
            <ProductID>P-11580V-5.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11580V-5.5</ProductID>
            <ProductID>P-11580V-5.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="308" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14878</Title>
      <Notes>
         <Note Audience="All" Ordinal="308" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Server executes to compromise MySQL Server.  Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14878</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.0</BaseScore>
            <Vector>AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="309" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14879</Title>
      <Notes>
         <Note Audience="All" Ordinal="309" Title="Details" Type="Details">Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO).  Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher.  While the vulnerability is in BI Publisher, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all BI Publisher accessible data as well as  unauthorized update, insert or delete access to some of BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14879</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="310" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14880</Title>
      <Notes>
         <Note Audience="All" Ordinal="310" Title="Details" Type="Details">Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO).  Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher.  While the vulnerability is in BI Publisher, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all BI Publisher accessible data as well as  unauthorized update, insert or delete access to some of BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14880</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1479V-5.5.0.0.0</ProductID>
            <ProductID>P-1479V-11.1.1.9.0</ProductID>
            <ProductID>P-1479V-12.2.1.3.0</ProductID>
            <ProductID>P-1479V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="311" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14881</Title>
      <Notes>
         <Note Audience="All" Ordinal="311" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is Prior to 6.1.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14881</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 6.1.16</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.0</BaseScore>
            <Vector>AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8370V-Prior to 6.1.16</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="312" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14882</Title>
      <Notes>
         <Note Audience="All" Ordinal="312" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).  Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14882</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="313" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14883</Title>
      <Notes>
         <Note Audience="All" Ordinal="313" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console).  Supported versions that are affected are 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0 and  14.1.1.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14883</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.2</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
            <ProductID>P-5242V-12.1.3.0.0</ProductID>
            <ProductID>P-5242V-12.2.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.4.0</ProductID>
            <ProductID>P-5242V-14.1.1.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="314" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14884</Title>
      <Notes>
         <Note Audience="All" Ordinal="314" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is Prior to 6.1.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14884</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 6.1.16</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.0</BaseScore>
            <Vector>AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8370V-Prior to 6.1.16</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="315" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14885</Title>
      <Notes>
         <Note Audience="All" Ordinal="315" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is Prior to 6.1.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14885</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 6.1.16</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.0</BaseScore>
            <Vector>AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8370V-Prior to 6.1.16</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="316" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14886</Title>
      <Notes>
         <Note Audience="All" Ordinal="316" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is Prior to 6.1.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14886</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 6.1.16</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.0</BaseScore>
            <Vector>AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8370V-Prior to 6.1.16</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="317" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14887</Title>
      <Notes>
         <Note Audience="All" Ordinal="317" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Universal Banking product of Oracle Financial Services Applications (component: Infrastructure).  Supported versions that are affected are 12.3.0 and  14.0.0-14.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14887</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-12.3.0</ProductID>
            <ProductID>P-9052V-14.0.0-14.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9052V-12.3.0</ProductID>
            <ProductID>P-9052V-14.0.0-14.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="318" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14888</Title>
      <Notes>
         <Note Audience="All" Ordinal="318" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14888</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="319" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14889</Title>
      <Notes>
         <Note Audience="All" Ordinal="319" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is Prior to 6.1.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14889</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 6.1.16</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.0</BaseScore>
            <Vector>AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8370V-Prior to 6.1.16</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="320" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14890</Title>
      <Notes>
         <Note Audience="All" Ordinal="320" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Direct Banking product of Oracle Financial Services Applications (component: Pre Login).  Supported versions that are affected are 12.0.1, 12.0.2 and  12.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Direct Banking.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle FLEXCUBE Direct Banking accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14890</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-12.0.1</ProductID>
            <ProductID>P-9111V-12.0.2</ProductID>
            <ProductID>P-9111V-12.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9111V-12.0.1</ProductID>
            <ProductID>P-9111V-12.0.2</ProductID>
            <ProductID>P-9111V-12.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="321" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14891</Title>
      <Notes>
         <Note Audience="All" Ordinal="321" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14891</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="322" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14892</Title>
      <Notes>
         <Note Audience="All" Ordinal="322" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is Prior to 6.1.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14892</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 6.1.16</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8370V-Prior to 6.1.16</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="323" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14893</Title>
      <Notes>
         <Note Audience="All" Ordinal="323" Title="Details" Type="Details">Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14893</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8478V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="324" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14894</Title>
      <Notes>
         <Note Audience="All" Ordinal="324" Title="Details" Type="Details">Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core).  Supported versions that are affected are 12.3.0 and  14.0.0-14.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Banking Corporate Lending accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14894</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12989V-12.3.0</ProductID>
            <ProductID>P-12989V-14.0.0-14.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-12989V-12.3.0</ProductID>
            <ProductID>P-12989V-14.0.0-14.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="325" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14895</Title>
      <Notes>
         <Note Audience="All" Ordinal="325" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component: System Wide).  Supported versions that are affected are 2.2.0.0.0, 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0 - 4.3.0.6.0, 4.4.0.0.0 and  4.4.0.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Utilities Framework.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Utilities Framework accessible data as well as  unauthorized read access to a subset of Oracle Utilities Framework accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14895</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2245V-2.2.0.0.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0 - 4.3.0.6.0</ProductID>
            <ProductID>P-2245V-4.4.0.0.0</ProductID>
            <ProductID>P-2245V-4.4.0.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2245V-2.2.0.0.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0 - 4.3.0.6.0</ProductID>
            <ProductID>P-2245V-4.4.0.0.0</ProductID>
            <ProductID>P-2245V-4.4.0.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="326" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14896</Title>
      <Notes>
         <Note Audience="All" Ordinal="326" Title="Details" Type="Details">Vulnerability in the Oracle Banking Payments product of Oracle Financial Services Applications (component: Core).  Supported versions that are affected are 14.1.0-14.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Payments.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Banking Payments accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14896</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13011V-14.1.0-14.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-13011V-14.1.0-14.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="327" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14897</Title>
      <Notes>
         <Note Audience="All" Ordinal="327" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Direct Banking product of Oracle Financial Services Applications (component: Pre Login).  Supported versions that are affected are 12.0.1, 12.0.2 and  12.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Direct Banking.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle FLEXCUBE Direct Banking accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14897</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-12.0.1</ProductID>
            <ProductID>P-9111V-12.0.2</ProductID>
            <ProductID>P-9111V-12.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9111V-12.0.1</ProductID>
            <ProductID>P-9111V-12.0.2</ProductID>
            <ProductID>P-9111V-12.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="328" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14898</Title>
      <Notes>
         <Note Audience="All" Ordinal="328" Title="Details" Type="Details">Vulnerability in the Oracle Application Express Packaged Apps component of Oracle Database Server.   The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Packaged Apps.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express Packaged Apps, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Application Express Packaged Apps accessible data as well as  unauthorized read access to a subset of Oracle Application Express Packaged Apps accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14898</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1348V-Prior to 20.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1348V-Prior to 20.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="329" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14899</Title>
      <Notes>
         <Note Audience="All" Ordinal="329" Title="Details" Type="Details">Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server.   The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Data Reporter.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express Data Reporter, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Application Express Data Reporter accessible data as well as  unauthorized read access to a subset of Oracle Application Express Data Reporter accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14899</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1348V-Prior to 20.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1348V-Prior to 20.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="330" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14900</Title>
      <Notes>
         <Note Audience="All" Ordinal="330" Title="Details" Type="Details">Vulnerability in the Oracle Application Express Group Calendar component of Oracle Database Server.   The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Group Calendar.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express Group Calendar, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Application Express Group Calendar accessible data as well as  unauthorized read access to a subset of Oracle Application Express Group Calendar accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14900</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1348V-Prior to 20.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1348V-Prior to 20.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="331" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-14901</Title>
      <Notes>
         <Note Audience="All" Ordinal="331" Title="Details" Type="Details">Vulnerability in the RDBMS Security component of Oracle Database Server.   The supported version that is affected is 19c. Easily exploitable vulnerability allows high privileged attacker having Analyze Any privilege with network access via Oracle Net to compromise RDBMS Security.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all RDBMS Security accessible data. CVSS 3.1 Base Score 4.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-14901</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="332" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-15389</Title>
      <Notes>
         <Note Audience="All" Ordinal="332" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology product of Oracle Fusion Middleware (component: Installation  (OpenJPEG)).  Supported versions that are affected are 8.5.5 and  8.5.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Outside In Technology.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology and  unauthorized read access to a subset of Oracle Outside In Technology accessible data.  Note: Outside In Technology is a suite of software development kits (SDKs). The protocol and CVSS score depend on the software that uses the Outside In Technology code. The CVSS score assumes that the software passes data received over a network directly to Outside In Technology code, but if data is not received over a network the CVSS score may be lower. CVSS 3.1 Base Score 6.5 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-15389</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.5.5</ProductID>
            <ProductID>P-2276V-8.5.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2276V-8.5.5</ProductID>
            <ProductID>P-2276V-8.5.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="333" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1730</Title>
      <Notes>
         <Note Audience="All" Ordinal="333" Title="Details" Type="Details">Vulnerability in the MySQL Workbench product of Oracle MySQL (component: MySQL Workbench (libssh)).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Workbench. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1730</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4627V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4627V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="334" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1938</Title>
      <Notes>
         <Note Audience="All" Ordinal="334" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files &amp; Attachments (Apache Tomcat)).  Supported versions that are affected are 9.3.3, 9.3.5 and  9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via AJP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1938</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.3</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
            <ProductID>P-4461V-9.3.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4461V-9.3.3</ProductID>
            <ProductID>P-4461V-9.3.5</ProductID>
            <ProductID>P-4461V-9.3.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="335" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1941</Title>
      <Notes>
         <Note Audience="All" Ordinal="335" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: IDIH (Apache ActiveMQ)).  Supported versions that are affected are IDIH: 8.0.0-8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Diameter Signaling Router (DSR), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Diameter Signaling Router (DSR) accessible data as well as  unauthorized read access to a subset of Oracle Communications Diameter Signaling Router (DSR) accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1941</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="336" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1941</Title>
      <Notes>
         <Note Audience="All" Ordinal="336" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking product of Oracle Financial Services Applications (component: Core (Apache ActiveMQ)).  Supported versions that are affected are 12.0.0 and  12.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Private Banking, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle FLEXCUBE Private Banking accessible data as well as  unauthorized read access to a subset of Oracle FLEXCUBE Private Banking accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1941</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="337" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1945</Title>
      <Notes>
         <Note Audience="All" Ordinal="337" Title="Details" Type="Details">Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Runtime Engine (Apache Ant)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Process Management Suite executes to compromise Oracle Business Process Management Suite.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Business Process Management Suite accessible data as well as  unauthorized access to critical data or complete access to all Oracle Business Process Management Suite accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1945</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5325V-12.2.1.3.0</ProductID>
            <ProductID>P-5325V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5325V-12.2.1.3.0</ProductID>
            <ProductID>P-5325V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="338" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1945</Title>
      <Notes>
         <Note Audience="All" Ordinal="338" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: IDIH (Apache Ant)).  Supported versions that are affected are IDIH: 8.0.0-8.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Diameter Signaling Router (DSR) executes to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Diameter Signaling Router (DSR) accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router (DSR) accessible data. CVSS 3.1 Base Score 6.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1945</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.7</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="339" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1945</Title>
      <Notes>
         <Note Audience="All" Ordinal="339" Title="Details" Type="Details">Vulnerability in the Oracle Retail Back Office product of Oracle Retail Applications (component: Security (Apache Ant)).  Supported versions that are affected are 14.0 and  14.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Back Office.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Back Office accessible data as well as  unauthorized access to critical data or complete access to all Oracle Retail Back Office accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1945</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2013V-14.0</ProductID>
            <ProductID>P-2013V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2013V-14.0</ProductID>
            <ProductID>P-2013V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="340" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1945</Title>
      <Notes>
         <Note Audience="All" Ordinal="340" Title="Details" Type="Details">Vulnerability in the Oracle Retail Central Office product of Oracle Retail Applications (component: Security (Apache Ant)).  Supported versions that are affected are 14.0 and  14.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Central Office.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Central Office accessible data as well as  unauthorized access to critical data or complete access to all Oracle Retail Central Office accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1945</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2016V-14.0</ProductID>
            <ProductID>P-2016V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2016V-14.0</ProductID>
            <ProductID>P-2016V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="341" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1945</Title>
      <Notes>
         <Note Audience="All" Ordinal="341" Title="Details" Type="Details">Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal (Apache Ant)).  Supported versions that are affected are 14.1, 15.0 and  16.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Integration Bus accessible data as well as  unauthorized access to critical data or complete access to all Oracle Retail Integration Bus accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1945</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1807V-14.1</ProductID>
            <ProductID>P-1807V-15.0</ProductID>
            <ProductID>P-1807V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1807V-14.1</ProductID>
            <ProductID>P-1807V-15.0</ProductID>
            <ProductID>P-1807V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="342" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1945</Title>
      <Notes>
         <Note Audience="All" Ordinal="342" Title="Details" Type="Details">Vulnerability in the Oracle Retail Point-of-Service product of Oracle Retail Applications (component: Security (Apache Ant)).  Supported versions that are affected are 14.0 and  14.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Point-of-Service.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Point-of-Service accessible data as well as  unauthorized access to critical data or complete access to all Oracle Retail Point-of-Service accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1945</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2017V-14.0</ProductID>
            <ProductID>P-2017V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2017V-14.0</ProductID>
            <ProductID>P-2017V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="343" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1945</Title>
      <Notes>
         <Note Audience="All" Ordinal="343" Title="Details" Type="Details">Vulnerability in the Oracle Retail Returns Management product of Oracle Retail Applications (component: Security (Apache Ant)).  Supported versions that are affected are 14.0 and  14.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Returns Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Retail Returns Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Retail Returns Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1945</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2020V-14.0</ProductID>
            <ProductID>P-2020V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2020V-14.0</ProductID>
            <ProductID>P-2020V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="344" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1945</Title>
      <Notes>
         <Note Audience="All" Ordinal="344" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component: General (Apache Ant)).  Supported versions that are affected are 2.2.0.0.0, 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0 - 4.3.0.6.0, 4.4.0.0.0 and  4.4.0.2.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Utilities Framework executes to compromise Oracle Utilities Framework.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Utilities Framework accessible data as well as  unauthorized access to critical data or complete access to all Oracle Utilities Framework accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1945</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2245V-2.2.0.0.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0 - 4.3.0.6.0</ProductID>
            <ProductID>P-2245V-4.4.0.0.0</ProductID>
            <ProductID>P-2245V-4.4.0.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.3</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2245V-2.2.0.0.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0 - 4.3.0.6.0</ProductID>
            <ProductID>P-2245V-4.4.0.0.0</ProductID>
            <ProductID>P-2245V-4.4.0.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="345" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1951</Title>
      <Notes>
         <Note Audience="All" Ordinal="345" Title="Details" Type="Details">Vulnerability in the Oracle Business Process Management Suite product of Oracle Fusion Middleware (component: Document Service (Apache Tika)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Business Process Management Suite executes to compromise Oracle Business Process Management Suite.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Business Process Management Suite. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1951</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5325V-12.2.1.3.0</ProductID>
            <ProductID>P-5325V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5325V-12.2.1.3.0</ProductID>
            <ProductID>P-5325V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="346" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1951</Title>
      <Notes>
         <Note Audience="All" Ordinal="346" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking product of Oracle Financial Services Applications (component: Core (Apache Tika)).  Supported versions that are affected are 12.0.0 and  12.1.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle FLEXCUBE Private Banking executes to compromise Oracle FLEXCUBE Private Banking.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle FLEXCUBE Private Banking. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1951</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="347" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1953</Title>
      <Notes>
         <Note Audience="All" Ordinal="347" Title="Details" Type="Details">Vulnerability in the Oracle Healthcare Foundation product of Oracle Health Sciences Applications (component: Self Service Analytics (Apache Commons Configuration)).  Supported versions that are affected are 7.1.1, 7.2.0, 7.2.1 and  7.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Foundation.  While the vulnerability is in Oracle Healthcare Foundation, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Foundation. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1953</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12950V-7.1.1</ProductID>
            <ProductID>P-12950V-7.2.0</ProductID>
            <ProductID>P-12950V-7.2.1</ProductID>
            <ProductID>P-12950V-7.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-12950V-7.1.1</ProductID>
            <ProductID>P-12950V-7.2.0</ProductID>
            <ProductID>P-12950V-7.2.1</ProductID>
            <ProductID>P-12950V-7.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="348" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1954</Title>
      <Notes>
         <Note Audience="All" Ordinal="348" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: IDIH (Apache CXF)).  Supported versions that are affected are IDIH: 8.0.0-8.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Diameter Signaling Router (DSR) executes to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Diameter Signaling Router (DSR) accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1954</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="349" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1954</Title>
      <Notes>
         <Note Audience="All" Ordinal="349" Title="Details" Type="Details">Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Core (Apache CXF)).  Supported versions that are affected are 8.2.0-8.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Element Manager executes to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Element Manager accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1954</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11052V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11052V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="350" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1954</Title>
      <Notes>
         <Note Audience="All" Ordinal="350" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: Core (Apache CXF)).  Supported versions that are affected are 8.2.0-8.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Session Report Manager executes to compromise Oracle Communications Session Report Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Session Report Manager accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1954</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10770V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10770V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="351" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1954</Title>
      <Notes>
         <Note Audience="All" Ordinal="351" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Route Manager product of Oracle Communications (component: Core (Apache CXF)).  Supported versions that are affected are 8.2.0-8.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Session Route Manager executes to compromise Oracle Communications Session Route Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Session Route Manager accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1954</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10771V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10771V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="352" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1954</Title>
      <Notes>
         <Note Audience="All" Ordinal="352" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Connector Framework (Apache CXF)).   The supported version that is affected is 13.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Enterprise Manager Base Platform executes to compromise Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1954</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-13.2.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1370V-13.2.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="353" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1954</Title>
      <Notes>
         <Note Audience="All" Ordinal="353" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Elastic Search (Apache CXF)).   The supported version that is affected is 8.56. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1954</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.56</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5085V-8.56</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="354" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1967</Title>
      <Notes>
         <Note Audience="All" Ordinal="354" Title="Details" Type="Details">Vulnerability in the Enterprise Manager for Storage Management product of Oracle Enterprise Manager (component: Privilege Management (OpenSSL)).  Supported versions that are affected are 13.3.0.0 and  13.4.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Enterprise Manager for Storage Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Enterprise Manager for Storage Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1967</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10303V-13.3.0.0</ProductID>
            <ProductID>P-10303V-13.4.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10303V-13.3.0.0</ProductID>
            <ProductID>P-10303V-13.4.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="355" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1967</Title>
      <Notes>
         <Note Audience="All" Ordinal="355" Title="Details" Type="Details">Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: SSL Module (OpenSSL)).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle HTTP Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HTTP Server. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1967</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1042V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1042V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="356" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-1967</Title>
      <Notes>
         <Note Audience="All" Ordinal="356" Title="Details" Type="Details">Vulnerability in the MySQL Workbench product of Oracle MySQL (component: Workbench: Security: Encryption (OpenSSL)).  Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via MySQL Workbench to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-1967</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4627V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4627V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="357" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-2555</Title>
      <Notes>
         <Note Audience="All" Ordinal="357" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: IDIH (Oracle Coherence)).  Supported versions that are affected are IDIH: 8.0.0-8.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router (DSR). CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-2555</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="358" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-2555</Title>
      <Notes>
         <Note Audience="All" Ordinal="358" Title="Details" Type="Details">Vulnerability in the Oracle Healthcare Data Repository product of Oracle Health Sciences Applications (component: Database Module (Oracle Coherence)).   The supported version that is affected is 7.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Data Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Healthcare Data Repository. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-2555</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9161V-7.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9161V-7.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="359" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-2555</Title>
      <Notes>
         <Note Audience="All" Ordinal="359" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework (Oracle Coherence)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-2555</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1696V-12.2.1.3.0</ProductID>
            <ProductID>P-1696V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1696V-12.2.1.3.0</ProductID>
            <ProductID>P-1696V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="360" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-3235</Title>
      <Notes>
         <Note Audience="All" Ordinal="360" Title="Details" Type="Details">Vulnerability in the Management Pack for Oracle GoldenGate product of Oracle Fusion Middleware (component: Monitor (SNMP)).   The supported version that is affected is 12.2.1.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via SNMP to compromise Management Pack for Oracle GoldenGate.  While the vulnerability is in Management Pack for Oracle GoldenGate, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Management Pack for Oracle GoldenGate. CVSS 3.1 Base Score 7.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-3235</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5759V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.7</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5759V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="361" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-4051</Title>
      <Notes>
         <Note Audience="All" Ordinal="361" Title="Details" Type="Details">Security-in-Depth issue in the MySQL Cluster product of Oracle MySQL (component: Cluster: Configuration (dojo)).  Supported versions that are affected are 7.3.30 and prior, 7.4.29 and prior, 7.5.19 and prior, 7.6.15 and prior and  8.0.21 and prior. This vulnerability cannot be exploited in the context of this product.CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-4051</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.3.30 and prior</ProductID>
            <ProductID>P-8479V-7.4.29 and prior</ProductID>
            <ProductID>P-8479V-7.5.19 and prior</ProductID>
            <ProductID>P-8479V-7.6.15 and prior</ProductID>
            <ProductID>P-8479V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8479V-7.3.30 and prior</ProductID>
            <ProductID>P-8479V-7.4.29 and prior</ProductID>
            <ProductID>P-8479V-7.5.19 and prior</ProductID>
            <ProductID>P-8479V-7.6.15 and prior</ProductID>
            <ProductID>P-8479V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="362" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5398</Title>
      <Notes>
         <Note Audience="All" Ordinal="362" Title="Details" Type="Details">Vulnerability in the Oracle Application Testing Suite product of Oracle Enterprise Manager (component: Load Testing for Web Apps (Spring Framework)).   The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Testing Suite.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5398</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4622V-13.3.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4622V-13.3.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="363" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5398</Title>
      <Notes>
         <Note Audience="All" Ordinal="363" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: IDIH (Spring Framework)).  Supported versions that are affected are IDIH: 8.0.0-8.2.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router (DSR). CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5398</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10899V-IDIH: 8.0.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="364" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5398</Title>
      <Notes>
         <Note Audience="All" Ordinal="364" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Connector Framework (Spring Framework)).   The supported version that is affected is 13.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Enterprise Manager Base Platform. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5398</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-13.2.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1370V-13.2.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="365" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5398</Title>
      <Notes>
         <Note Audience="All" Ordinal="365" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking product of Oracle Financial Services Applications (component: Core (Spring Framework)).  Supported versions that are affected are 12.0.0 and  12.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle FLEXCUBE Private Banking. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5398</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="366" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5398</Title>
      <Notes>
         <Note Audience="All" Ordinal="366" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Regulatory Reporting with AgileREPORTER product of Oracle Financial Services Applications (component: Core (Spring Framework)).   The supported version that is affected is 8.0.9.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Regulatory Reporting with AgileREPORTER.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Regulatory Reporting with AgileREPORTER. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5398</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13077V-8.0.9.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-13077V-8.0.9.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="367" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5398</Title>
      <Notes>
         <Note Audience="All" Ordinal="367" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Policy Administration J2EE product of Oracle Insurance Applications (component: Admin Console (Spring Framework)).   The supported version that is affected is 11.2.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration J2EE.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Insurance Policy Administration J2EE. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5398</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5279V-11.2.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5279V-11.2.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="368" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5408</Title>
      <Notes>
         <Note Audience="All" Ordinal="368" Title="Details" Type="Details">Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Core (Spring Security)).  Supported versions that are affected are 8.2.0-8.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Element Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5408</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11052V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11052V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="369" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5408</Title>
      <Notes>
         <Note Audience="All" Ordinal="369" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: Core (Spring Security)).  Supported versions that are affected are 8.2.0-8.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Session Report Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Session Report Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5408</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10770V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10770V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="370" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-5408</Title>
      <Notes>
         <Note Audience="All" Ordinal="370" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Route Manager product of Oracle Communications (component: Core (Spring Security)).  Supported versions that are affected are 8.2.0-8.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Session Route Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Session Route Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-5408</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10771V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10771V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="371" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-8174</Title>
      <Notes>
         <Note Audience="All" Ordinal="371" Title="Details" Type="Details">Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: JS module (Node.js)).  Supported versions that are affected are 7.3.30 and prior, 7.4.29 and prior, 7.5.19 and prior, 7.6.15 and prior and  8.0.21 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in takeover of MySQL Cluster. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-8174</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.3.30 and prior</ProductID>
            <ProductID>P-8479V-7.4.29 and prior</ProductID>
            <ProductID>P-8479V-7.5.19 and prior</ProductID>
            <ProductID>P-8479V-7.6.15 and prior</ProductID>
            <ProductID>P-8479V-8.0.21 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8479V-7.3.30 and prior</ProductID>
            <ProductID>P-8479V-7.4.29 and prior</ProductID>
            <ProductID>P-8479V-7.5.19 and prior</ProductID>
            <ProductID>P-8479V-7.6.15 and prior</ProductID>
            <ProductID>P-8479V-8.0.21 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="372" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9281</Title>
      <Notes>
         <Note Audience="All" Ordinal="372" Title="Details" Type="Details">Vulnerability in the Oracle Application Express component of Oracle Database Server.   The supported version that is affected is Prior to 20.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as  unauthorized read access to a subset of Oracle Application Express accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9281</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1348V-Prior to 20.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1348V-Prior to 20.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="373" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9281</Title>
      <Notes>
         <Note Audience="All" Ordinal="373" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Blogs and Wikis (CKEditor)).  Supported versions that are affected are 11.1.1.9.0, 12.2.1.3.0 and  12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data as well as  unauthorized read access to a subset of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9281</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1696V-11.1.1.9.0</ProductID>
            <ProductID>P-1696V-12.2.1.3.0</ProductID>
            <ProductID>P-1696V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1696V-11.1.1.9.0</ProductID>
            <ProductID>P-1696V-12.2.1.3.0</ProductID>
            <ProductID>P-1696V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="374" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9410</Title>
      <Notes>
         <Note Audience="All" Ordinal="374" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Broker product of Oracle Retail Applications (component: Order Broker Foundation (jasperreports_server)).  Supported versions that are affected are 15.0 and  16.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Order Broker.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Retail Order Broker. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9410</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11520V-15.0</ProductID>
            <ProductID>P-11520V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11520V-15.0</ProductID>
            <ProductID>P-11520V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="375" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9484</Title>
      <Notes>
         <Note Audience="All" Ordinal="375" Title="Details" Type="Details">Vulnerability in the Oracle Communications Diameter Signaling Router (DSR) product of Oracle Communications (component: Core (Apache Tomcat)).  Supported versions that are affected are 8.0.0.0-8.4.0.5. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Diameter Signaling Router (DSR) executes to compromise Oracle Communications Diameter Signaling Router (DSR).  Successful attacks of this vulnerability can result in takeover of Oracle Communications Diameter Signaling Router (DSR). CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9484</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10899V-8.0.0.0-8.4.0.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10899V-8.0.0.0-8.4.0.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="376" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9484</Title>
      <Notes>
         <Note Audience="All" Ordinal="376" Title="Details" Type="Details">Vulnerability in the Oracle Communications Element Manager product of Oracle Communications (component: Core (Apache Tomcat)).  Supported versions that are affected are 8.2.0-8.2.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Element Manager executes to compromise Oracle Communications Element Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Element Manager. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9484</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11052V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11052V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="377" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9484</Title>
      <Notes>
         <Note Audience="All" Ordinal="377" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Report Manager product of Oracle Communications (component: Core (Apache Tomcat)).  Supported versions that are affected are 8.2.0-8.2.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Session Report Manager executes to compromise Oracle Communications Session Report Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Report Manager. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9484</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10770V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10770V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="378" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9484</Title>
      <Notes>
         <Note Audience="All" Ordinal="378" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Route Manager product of Oracle Communications (component: Core (Apache Tomcat)).  Supported versions that are affected are 8.2.0-8.2.2. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Session Route Manager executes to compromise Oracle Communications Session Route Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Route Manager. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9484</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10771V-8.2.0-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10771V-8.2.0-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="379" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9484</Title>
      <Notes>
         <Note Audience="All" Ordinal="379" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality Guest Access product of Oracle Hospitality Applications (component: Base (Apache Tomcat)).  Supported versions that are affected are 4.2.0 and  4.2.1. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hospitality Guest Access executes to compromise Oracle Hospitality Guest Access.  Successful attacks of this vulnerability can result in takeover of Oracle Hospitality Guest Access. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9484</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12617V-4.2.0</ProductID>
            <ProductID>P-12617V-4.2.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-12617V-4.2.0</ProductID>
            <ProductID>P-12617V-4.2.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="380" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9484</Title>
      <Notes>
         <Note Audience="All" Ordinal="380" Title="Details" Type="Details">Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server (Apache Tomcat)).  Supported versions that are affected are 12.2.1.3.0 and  12.2.1.4.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Managed File Transfer executes to compromise Oracle Managed File Transfer.  Successful attacks of this vulnerability can result in takeover of Oracle Managed File Transfer. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9484</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10198V-12.2.1.3.0</ProductID>
            <ProductID>P-10198V-12.2.1.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10198V-12.2.1.3.0</ProductID>
            <ProductID>P-10198V-12.2.1.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="381" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9484</Title>
      <Notes>
         <Note Audience="All" Ordinal="381" Title="Details" Type="Details">Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Install (Apache Tomcat)).   The supported version that is affected is 6.3.7. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Transportation Management executes to compromise Oracle Transportation Management.  Successful attacks of this vulnerability can result in takeover of Oracle Transportation Management. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9484</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1991V-6.3.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1991V-6.3.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="382" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="382" Title="Details" Type="Details">Vulnerability in the Oracle Communications Application Session Controller product of Oracle Communications (component: WS and WEB (Apache Log4j)).   The supported version that is affected is 3.9m0p1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise Oracle Communications Application Session Controller.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Application Session Controller accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10769V-3.9m0p1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10769V-3.9m0p1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="383" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="383" Title="Details" Type="Details">Vulnerability in the Oracle Communications Billing and Revenue Management product of Oracle Communications Applications (component: Billing Operation Center and Oracle Communication Billing Care (Apache Log4j)).  Supported versions that are affected are 7.5.0.23.0 and  12.0.0.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise Oracle Communications Billing and Revenue Management.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Billing and Revenue Management accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2136V-7.5.0.23.0</ProductID>
            <ProductID>P-2136V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2136V-7.5.0.23.0</ProductID>
            <ProductID>P-2136V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="384" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="384" Title="Details" Type="Details">Vulnerability in the Oracle Communications Offline Mediation Controller product of Oracle Communications Applications (component: Core (Apache Log4j)).   The supported version that is affected is 12.0.0.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise Oracle Communications Offline Mediation Controller.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Offline Mediation Controller accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2269V-12.0.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2269V-12.0.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="385" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="385" Title="Details" Type="Details">Vulnerability in the Oracle Communications Services Gatekeeper product of Oracle Communications (component: Media Control UI (Apache Log4j)).   The supported version that is affected is 7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise Oracle Communications Services Gatekeeper.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Services Gatekeeper accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5381V-7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5381V-7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="386" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="386" Title="Details" Type="Details">Vulnerability in the Oracle Communications Unified Inventory Management product of Oracle Communications Applications (component: Core (Apache Log4j)).  Supported versions that are affected are 7.3.0 and  7.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise Oracle Communications Unified Inventory Management.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Unified Inventory Management accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4516V-7.3.0</ProductID>
            <ProductID>P-4516V-7.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-4516V-7.3.0</ProductID>
            <ProductID>P-4516V-7.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="387" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="387" Title="Details" Type="Details">Vulnerability in the Enterprise Manager for Peoplesoft product of Oracle Enterprise Manager (component: PSEM Plugin (Apache Log4j)).   The supported version that is affected is 13.4.1.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise Enterprise Manager for Peoplesoft.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Enterprise Manager for Peoplesoft accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2131V-13.4.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2131V-13.4.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="388" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="388" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Core Banking product of Oracle Financial Services Applications (component: Core (Apache Log4j)).  Supported versions that are affected are 5.2.0 and  11.5.0-11.7.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise Oracle FLEXCUBE Core Banking.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle FLEXCUBE Core Banking accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9101V-5.2.0</ProductID>
            <ProductID>P-9101V-11.5.0-11.7.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9101V-5.2.0</ProductID>
            <ProductID>P-9101V-11.5.0-11.7.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="389" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="389" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking product of Oracle Financial Services Applications (component: Core (Apache Log4j)).  Supported versions that are affected are 12.0.0 and  12.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise Oracle FLEXCUBE Private Banking.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle FLEXCUBE Private Banking accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="390" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="390" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (Apache Log4j)).  Supported versions that are affected are 8.0.6-8.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Financial Services Analytical Applications Infrastructure accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5680V-8.0.6-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5680V-8.0.6-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="391" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="391" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Institutional Performance Analytics product of Oracle Financial Services Applications (component: User Interface (Apache Log4j)).  Supported versions that are affected are 8.0.6, 8.7.0 and  8.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise Oracle Financial Services Institutional Performance Analytics.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Financial Services Institutional Performance Analytics accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10215V-8.0.6</ProductID>
            <ProductID>P-10215V-8.7.0</ProductID>
            <ProductID>P-10215V-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10215V-8.0.6</ProductID>
            <ProductID>P-10215V-8.7.0</ProductID>
            <ProductID>P-10215V-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="392" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="392" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Market Risk Measurement and Management product of Oracle Financial Services Applications (component: Infrastructure (Apache log4j)).  Supported versions that are affected are 8.0.6, 8.0.8 and  8.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise Oracle Financial Services Market Risk Measurement and Management.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Financial Services Market Risk Measurement and Management accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-13111V-8.0.6</ProductID>
            <ProductID>P-13111V-8.0.8</ProductID>
            <ProductID>P-13111V-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-13111V-8.0.6</ProductID>
            <ProductID>P-13111V-8.0.8</ProductID>
            <ProductID>P-13111V-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="393" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="393" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Price Creation and Discovery product of Oracle Financial Services Applications (component: User Interface (Apache Log4j)).  Supported versions that are affected are 8.0.6 and  8.0.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise Oracle Financial Services Price Creation and Discovery.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Financial Services Price Creation and Discovery accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5749V-8.0.6</ProductID>
            <ProductID>P-5749V-8.0.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5749V-8.0.6</ProductID>
            <ProductID>P-5749V-8.0.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="394" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="394" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Retail Customer Analytics product of Oracle Financial Services Applications (component: User Interface (Apache Log4j)).   The supported version that is affected is 8.0.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise Oracle Financial Services Retail Customer Analytics.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Financial Services Retail Customer Analytics accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10214V-8.0.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10214V-8.0.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="395" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="395" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Insbridge Rating and Underwriting product of Oracle Insurance Applications (component: Framework Administrator IBFA (Apache Log4j)).  Supported versions that are affected are 5.0.0.0 - 5.6.0.0 and  5.6.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise Oracle Insurance Insbridge Rating and Underwriting.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Insurance Insbridge Rating and Underwriting accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5484V-5.0.0.0 - 5.6.0.0</ProductID>
            <ProductID>P-5484V-5.6.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5484V-5.0.0.0 - 5.6.0.0</ProductID>
            <ProductID>P-5484V-5.6.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="396" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="396" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Policy Administration J2EE product of Oracle Insurance Applications (component: Architecture (Apache Log4j)).  Supported versions that are affected are 10.2.0.37, 10.2.4.12, 11.0.2.25, 11.1.0.15 and  11.2.0.26. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise Oracle Insurance Policy Administration J2EE.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Insurance Policy Administration J2EE accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5279V-10.2.0.37</ProductID>
            <ProductID>P-5279V-10.2.4.12</ProductID>
            <ProductID>P-5279V-11.0.2.25</ProductID>
            <ProductID>P-5279V-11.1.0.15</ProductID>
            <ProductID>P-5279V-11.2.0.26</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5279V-10.2.0.37</ProductID>
            <ProductID>P-5279V-10.2.4.12</ProductID>
            <ProductID>P-5279V-11.0.2.25</ProductID>
            <ProductID>P-5279V-11.1.0.15</ProductID>
            <ProductID>P-5279V-11.2.0.26</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="397" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="397" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Rules Palette product of Oracle Insurance Applications (component: Architecture (Apache Log4j)).  Supported versions that are affected are 10.2.0.37, 10.2.4.12, 11.0.2.25, 11.1.0.15 and  11.2.0.26. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise Oracle Insurance Rules Palette.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Insurance Rules Palette accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5288V-10.2.0.37</ProductID>
            <ProductID>P-5288V-10.2.4.12</ProductID>
            <ProductID>P-5288V-11.0.2.25</ProductID>
            <ProductID>P-5288V-11.1.0.15</ProductID>
            <ProductID>P-5288V-11.2.0.26</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5288V-10.2.0.37</ProductID>
            <ProductID>P-5288V-10.2.4.12</ProductID>
            <ProductID>P-5288V-11.0.2.25</ProductID>
            <ProductID>P-5288V-11.1.0.15</ProductID>
            <ProductID>P-5288V-11.2.0.26</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="398" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="398" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Tools Admin API  (Apache Log4j)).  Supported versions that are affected are 8.56, 8.57 and  8.58. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="399" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="399" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Mgmt (Apache Log4j)).  Supported versions that are affected are 8.56, 8.57 and  8.58. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5085V-8.56</ProductID>
            <ProductID>P-5085V-8.57</ProductID>
            <ProductID>P-5085V-8.58</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="400" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="400" Title="Details" Type="Details">Vulnerability in the Oracle Policy Automation product of Oracle Policy Automation (component: Core (Apache Log4j)).  Supported versions that are affected are 12.2.0 - 12.2.20. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Policy Automation.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Policy Automation accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5624V-12.2.0 - 12.2.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5624V-12.2.0 - 12.2.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="401" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="401" Title="Details" Type="Details">Vulnerability in the Oracle Policy Automation Connector for Siebel product of Oracle Policy Automation (component: Core (Apache Log4j)).   The supported version that is affected is 10.4.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Policy Automation Connector for Siebel.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Policy Automation Connector for Siebel accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5627V-10.4.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5627V-10.4.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="402" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="402" Title="Details" Type="Details">Vulnerability in the Oracle Policy Automation for Mobile Devices product of Oracle Policy Automation (component: Core (Apache Log4j)).  Supported versions that are affected are 12.2.0 - 12.2.20. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Policy Automation for Mobile Devices.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Policy Automation for Mobile Devices accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5626V-12.2.0 - 12.2.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5626V-12.2.0 - 12.2.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="403" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="403" Title="Details" Type="Details">Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Core (Apache Log4j)).  Supported versions that are affected are 18.8 and  19.12. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise Primavera Unifier.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Primavera Unifier accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="404" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="404" Title="Details" Type="Details">Vulnerability in the Oracle Retail Advanced Inventory Planning product of Oracle Retail Applications (component: AIP Dashboard  (Apache Log4j)).   The supported version that is affected is 14.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Advanced Inventory Planning.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Retail Advanced Inventory Planning accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1785V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1785V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="405" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="405" Title="Details" Type="Details">Vulnerability in the Oracle Retail Assortment Planning product of Oracle Retail Applications (component: Application Core  (Apache Log4j)).  Supported versions that are affected are 15.0.3.0 and  16.0.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Assortment Planning.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Retail Assortment Planning accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1788V-15.0.3.0</ProductID>
            <ProductID>P-1788V-16.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1788V-15.0.3.0</ProductID>
            <ProductID>P-1788V-16.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="406" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="406" Title="Details" Type="Details">Vulnerability in the Oracle Retail Bulk Data Integration product of Oracle Retail Applications (component: BDI Job Scheduler (Apache Log4j)).  Supported versions that are affected are 15.0.3.0 and  16.0.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Bulk Data Integration.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Retail Bulk Data Integration accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12968V-15.0.3.0</ProductID>
            <ProductID>P-12968V-16.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-12968V-15.0.3.0</ProductID>
            <ProductID>P-12968V-16.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="407" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="407" Title="Details" Type="Details">Vulnerability in the Oracle Retail Integration Bus product of Oracle Retail Applications (component: RIB Kernal  (Apache Log4j)).  Supported versions that are affected are 14.1, 15.0 and  16.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Integration Bus.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Retail Integration Bus accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1807V-14.1</ProductID>
            <ProductID>P-1807V-15.0</ProductID>
            <ProductID>P-1807V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1807V-14.1</ProductID>
            <ProductID>P-1807V-15.0</ProductID>
            <ProductID>P-1807V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="408" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="408" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Broker product of Oracle Retail Applications (component: Store Connect (Apache Log4j)).  Supported versions that are affected are 16.0, 18.0, 19.0, 19.1, 19.2 and  19.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Order Broker.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Retail Order Broker accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11520V-16.0</ProductID>
            <ProductID>P-11520V-18.0</ProductID>
            <ProductID>P-11520V-19.0</ProductID>
            <ProductID>P-11520V-19.1</ProductID>
            <ProductID>P-11520V-19.2</ProductID>
            <ProductID>P-11520V-19.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11520V-16.0</ProductID>
            <ProductID>P-11520V-18.0</ProductID>
            <ProductID>P-11520V-19.0</ProductID>
            <ProductID>P-11520V-19.1</ProductID>
            <ProductID>P-11520V-19.2</ProductID>
            <ProductID>P-11520V-19.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="409" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="409" Title="Details" Type="Details">Vulnerability in the Oracle Retail Predictive Application Server product of Oracle Retail Applications (component: RPAS Fusion Client  (Apache Log4j)).  Supported versions that are affected are 14.1.3.0, 
15.0.3.0 and 
16.0.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Predictive Application Server.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Retail Predictive Application Server accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1823V-14.1.3.0</ProductID>
            <ProductID>P-1823V-15.0.3.0</ProductID>
            <ProductID>P-1823V-16.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-1823V-14.1.3.0</ProductID>
            <ProductID>P-1823V-15.0.3.0</ProductID>
            <ProductID>P-1823V-16.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="410" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="410" Title="Details" Type="Details">Security-in-Depth issue in the Oracle Spatial and Graph (Apache Log4j) component of Oracle Database Server.  Supported versions that are affected are 12.2.0.1, 18c and  19c. This vulnerability cannot be exploited in the context of this product.CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-619V-12.2.0.1</ProductID>
            <ProductID>P-619V-18c</ProductID>
            <ProductID>P-619V-19c</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-619V-12.2.0.1</ProductID>
            <ProductID>P-619V-18c</ProductID>
            <ProductID>P-619V-19c</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="411" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="411" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Framework product of Oracle Utilities Applications (component: Common (Apache Log4j)).  Supported versions that are affected are 2.2.0.0.0, 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0 - 4.3.0.6.0, 4.4.0.0.0 and  4.4.0.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Framework.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Utilities Framework accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2245V-2.2.0.0.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0 - 4.3.0.6.0</ProductID>
            <ProductID>P-2245V-4.4.0.0.0</ProductID>
            <ProductID>P-2245V-4.4.0.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-2245V-2.2.0.0.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0 - 4.3.0.6.0</ProductID>
            <ProductID>P-2245V-4.4.0.0.0</ProductID>
            <ProductID>P-2245V-4.4.0.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="412" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9488</Title>
      <Notes>
         <Note Audience="All" Ordinal="412" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core (Apache Log4j)).   The supported version that is affected is 10.3.6.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTPS to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5242V-10.3.6.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="413" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9489</Title>
      <Notes>
         <Note Audience="All" Ordinal="413" Title="Details" Type="Details">Vulnerability in the Oracle Communications Messaging Server product of Oracle Communications Applications (component: Core (Apache Tika)).   The supported version that is affected is 8.1. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Messaging Server executes to compromise Oracle Communications Messaging Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Messaging Server. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9489</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8496V-8.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-8496V-8.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="414" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9489</Title>
      <Notes>
         <Note Audience="All" Ordinal="414" Title="Details" Type="Details">Vulnerability in the Primavera Unifier product of Oracle Construction and Engineering (component: Platform (Apache Tika)).  Supported versions that are affected are 16.1, 16.2, 17.7-17.12, 18.8 and  19.12. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Primavera Unifier executes to compromise Primavera Unifier.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Primavera Unifier. CVSS 3.1 Base Score 5.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9489</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10354V-16.1</ProductID>
            <ProductID>P-10354V-16.2</ProductID>
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10354V-16.1</ProductID>
            <ProductID>P-10354V-16.2</ProductID>
            <ProductID>P-10354V-17.7-17.12</ProductID>
            <ProductID>P-10354V-18.8</ProductID>
            <ProductID>P-10354V-19.12</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="415" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9546</Title>
      <Notes>
         <Note Audience="All" Ordinal="415" Title="Details" Type="Details">Security-in-Depth issue in the Big Data Spatial and Graph product of Oracle Big Data Graph (component: Property Graph Analytics (jackson-databind)).   The supported version that is affected is Prior to 20.2. This vulnerability cannot be exploited in the context of this product. Note: CVEs addressed by this patch are not exploitable in the context of Property Graph and Analytics in Big Data Spatial and Graph product, thus the CVSS score is 0.0. CVSS 3.1 Base Score 0.0. CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9546</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11528V-Prior to 20.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  0.0</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-11528V-Prior to 20.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="416" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9546</Title>
      <Notes>
         <Note Audience="All" Ordinal="416" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure product of Oracle Financial Services Applications (component: Infrastructure (jackson-databind)).  Supported versions that are affected are 8.0.6-8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9546</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5680V-8.0.6-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5680V-8.0.6-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="417" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9546</Title>
      <Notes>
         <Note Audience="All" Ordinal="417" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Institutional Performance Analytics product of Oracle Financial Services Applications (component: User Interface (jackson-databind)).  Supported versions that are affected are 8.0.6, 8.7.0 and  8.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Institutional Performance Analytics.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Institutional Performance Analytics. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9546</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10215V-8.0.6</ProductID>
            <ProductID>P-10215V-8.7.0</ProductID>
            <ProductID>P-10215V-8.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10215V-8.0.6</ProductID>
            <ProductID>P-10215V-8.7.0</ProductID>
            <ProductID>P-10215V-8.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="418" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9546</Title>
      <Notes>
         <Note Audience="All" Ordinal="418" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Price Creation and Discovery product of Oracle Financial Services Applications (component: User Interface (jackson-databind)).  Supported versions that are affected are 8.0.6 and  8.0.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Price Creation and Discovery.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Price Creation and Discovery. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9546</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5749V-8.0.6</ProductID>
            <ProductID>P-5749V-8.0.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5749V-8.0.6</ProductID>
            <ProductID>P-5749V-8.0.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="419" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9546</Title>
      <Notes>
         <Note Audience="All" Ordinal="419" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Retail Customer Analytics product of Oracle Financial Services Applications (component: User Interface (jackson-databind)).   The supported version that is affected is 8.0.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Retail Customer Analytics.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Retail Customer Analytics. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9546</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10214V-8.0.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10214V-8.0.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="420" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9546</Title>
      <Notes>
         <Note Audience="All" Ordinal="420" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Policy Administration J2EE product of Oracle Insurance Applications (component: Architecture (jackson-databind)).  Supported versions that are affected are 11.0.2.25 and  11.1.0.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Policy Administration J2EE.  Successful attacks of this vulnerability can result in takeover of Oracle Insurance Policy Administration J2EE. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9546</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5279V-11.0.2.25</ProductID>
            <ProductID>P-5279V-11.1.0.15</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-5279V-11.0.2.25</ProductID>
            <ProductID>P-5279V-11.1.0.15</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="421" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2020-9546</Title>
      <Notes>
         <Note Audience="All" Ordinal="421" Title="Details" Type="Details">Vulnerability in the Oracle Retail Service Backbone product of Oracle Retail Applications (component: RSB kernel (jackson-databind)).  Supported versions that are affected are 14.1, 15.0 and  16.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Service Backbone.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Service Backbone. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Security patch has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2020-9546</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10867V-14.1</ProductID>
            <ProductID>P-10867V-15.0</ProductID>
            <ProductID>P-10867V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Patch">
            <Description>CPUOct2020</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>https://www.oracle.com/security-alerts/cpuoct2020.html</URL>
            <ProductID>P-10867V-14.1</ProductID>
            <ProductID>P-10867V-15.0</ProductID>
            <ProductID>P-10867V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
</cvrf:cvrfdoc>
