
{
    "document": {
        "category": "csaf_security_advisory",
        "csaf_version": "2.0",
        "distribution": {
            "text": "Copyright \u00a9 Oracle. All rights reserved.",
            "tlp": {
                "label": "WHITE",
                "url": "https://www.first.org/tlp"
            }
        },
        "lang": "en",
        "publisher": {
            "category": "vendor",
            "name": "Oracle",
            "namespace": "https://www.oracle.com"
        },
        "references": [
            {
                "summary": "URL to html version of Advisory",
                "url": "https://www.oracle.com/security-alerts/cspusep2026.html"
            },
            {
                "category": "self",
                "summary": "Canonical URL for this CSAF document.",
                "url": "https://www.oracle.com/docs/tech/security-alerts/cspusep2026csaf.json"
            }
        ],
        "title": "Oracle Critical Security Patch Update Advisory - September 2026 - Oracle CSAF",
        "tracking": {
            "current_release_date": "2026-09-15T13:00:00-07:00",
            "id": "cspusep2026csaf",
            "initial_release_date": "2026-09-15T13:00:00-07:00",
            "revision_history": [
                {
                    "date": "2026-09-15T13:00:00-07:00",
                    "number": "1",
                    "summary": "Initial Release"
                }
            ],
            "status": "final",
            "version": "1"
        }
    },
    "product_tree": {
        "branches": [
            {
                "branches": [
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle BI Publisher Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle BI Publisher Version 12.2.1.4.0",
                                            "product_id": "P-1479V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:bi_publisher:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle BI Publisher Version 26.01.0.0.0",
                                        "product": {
                                            "name": "Oracle BI Publisher Version 26.01.0.0.0",
                                            "product_id": "P-1479V-26.01.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:bi_publisher:26.01.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle BI Publisher Version 8.2.0.0.0",
                                        "product": {
                                            "name": "Oracle BI Publisher Version 8.2.0.0.0",
                                            "product_id": "P-1479V-8.2.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:bi_publisher:8.2.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle BI Publisher"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Business Intelligence Enterprise Edition Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Business Intelligence Enterprise Edition Version 12.2.1.4.0",
                                            "product_id": "P-2025V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Business Intelligence Enterprise Edition Version 26.01.0.0.0",
                                        "product": {
                                            "name": "Oracle Business Intelligence Enterprise Edition Version 26.01.0.0.0",
                                            "product_id": "P-2025V-26.01.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:business_intelligence:26.01.0.0.0:*:*:*:enterprise:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Business Intelligence Enterprise Edition Version 8.2.0.0.0",
                                        "product": {
                                            "name": "Oracle Business Intelligence Enterprise Edition Version 8.2.0.0.0",
                                            "product_id": "P-2025V-8.2.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:business_intelligence:8.2.0.0.0:*:*:*:enterprise:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Business Intelligence Enterprise Edition"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Analytics"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Application Testing Suite Version 13.3.0.1",
                                        "product": {
                                            "name": "Oracle Application Testing Suite Version 13.3.0.1",
                                            "product_id": "P-4622V-13.3.0.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Application Testing Suite"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Application Testing Suite"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Autonomous Health Framework Version 26.2",
                                        "product": {
                                            "name": "Oracle Autonomous Health Framework Version 26.2",
                                            "product_id": "P-14634V-26.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:autonomous_health_framework:26.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Autonomous Health Framework Version 26.3.1",
                                        "product": {
                                            "name": "Oracle Autonomous Health Framework Version 26.3.1",
                                            "product_id": "P-14634V-26.3.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:autonomous_health_framework:26.3.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Autonomous Health Framework Version 26.5.3",
                                        "product": {
                                            "name": "Oracle Autonomous Health Framework Version 26.5.3",
                                            "product_id": "P-14634V-26.5.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:autonomous_health_framework:26.5.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Autonomous Health Framework Version 26.8",
                                        "product": {
                                            "name": "Oracle Autonomous Health Framework Version 26.8",
                                            "product_id": "P-14634V-26.8",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:autonomous_health_framework:26.8:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Autonomous Health Framework"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Autonomous Health Framework"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Endeca Application Controller) Version 11.4.0",
                                        "product": {
                                            "name": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Endeca Application Controller) Version 11.4.0",
                                            "product_id": "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Endeca Application Controller)V-11.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:commerce_guided_search_\\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager) Version 11.4.0",
                                        "product": {
                                            "name": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager) Version 11.4.0",
                                            "product_id": "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:commerce_guided_search_\\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge) Version 11.4.0",
                                        "product": {
                                            "name": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge) Version 11.4.0",
                                            "product_id": "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:commerce_guided_search_\\/_oracle_commerce_experience_manager:11.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Commerce Guided Search / Oracle Commerce Experience Manager"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Commerce"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP) Version 25.2.201",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP) Version 25.2.201",
                                            "product_id": "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.201",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:25.2.201:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP) Version 26.1.200",
                                        "product": {
                                            "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP) Version 26.1.200",
                                            "product_id": "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-26.1.200",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:26.1.200:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Cloud Native Core Security Edge Protection Proxy"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications MetaSolv Solution Module - ASR Version 70.0.0",
                                        "product": {
                                            "name": "Oracle Communications MetaSolv Solution Module - ASR Version 70.0.0",
                                            "product_id": "P-2281V-70.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_metasolv_solution_module_-_asr:70.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications MetaSolv Solution Module - ASR"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Operations Monitor Version 6.1",
                                        "product": {
                                            "name": "Oracle Communications Operations Monitor Version 6.1",
                                            "product_id": "P-10761V-6.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_operations_monitor:6.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Operations Monitor"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/8.0-8.1",
                                        "product": {
                                            "name": "Oracle Communications Service Catalog and Design Version 8.0-8.1",
                                            "product_id": "P-2283V-8.0-8.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_service_catalog_and_design:8.0-8.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/8.0-8.3",
                                        "product": {
                                            "name": "Oracle Communications Service Catalog and Design Version 8.0-8.3",
                                            "product_id": "P-2283V-8.0-8.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_service_catalog_and_design:8.0-8.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Service Catalog and Design"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/6.1.1-7.0.0",
                                        "product": {
                                            "name": "Oracle Communications Unified Assurance Version 6.1.1-7.0.0",
                                            "product_id": "P-14597V-6.1.1-7.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_unified_assurance:6.1.1-7.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Communications Unified Assurance Version 7.0.0",
                                        "product": {
                                            "name": "Oracle Communications Unified Assurance Version 7.0.0",
                                            "product_id": "P-14597V-7.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:communications_unified_assurance:7.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Communications Unified Assurance"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Communications"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/19.3-19.32",
                                        "product": {
                                            "name": "Oracle Database Server(Oracle Net Services) Version 19.3-19.32",
                                            "product_id": "P-5(Oracle Net Services)V-19.3-19.32",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_e_net_services:19.3-19.32:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/19.3-19.32",
                                        "product": {
                                            "name": "Oracle Database Server(Oracle Text) Version 19.3-19.32",
                                            "product_id": "P-5(Oracle Text)V-19.3-19.32",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_e_text:19.3-19.32:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/19.3-19.32",
                                        "product": {
                                            "name": "Oracle Database Server(Oracle XML Developers Kit) Version 19.3-19.32",
                                            "product_id": "P-5(Oracle XML Developers Kit)V-19.3-19.32",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_e_xml_developers_kit:19.3-19.32:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/19.3-19.32",
                                        "product": {
                                            "name": "Oracle Database Server(RDBMS) Version 19.3-19.32",
                                            "product_id": "P-5(RDBMS)V-19.3-19.32",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_rdbms:19.3-19.32:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/21.3-21.23",
                                        "product": {
                                            "name": "Oracle Database Server(Oracle Net Services) Version 21.3-21.23",
                                            "product_id": "P-5(Oracle Net Services)V-21.3-21.23",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_e_net_services:21.3-21.23:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/21.3-21.23",
                                        "product": {
                                            "name": "Oracle Database Server(Oracle Text) Version 21.3-21.23",
                                            "product_id": "P-5(Oracle Text)V-21.3-21.23",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_e_text:21.3-21.23:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/21.3-21.23",
                                        "product": {
                                            "name": "Oracle Database Server(Oracle XML Developers Kit) Version 21.3-21.23",
                                            "product_id": "P-5(Oracle XML Developers Kit)V-21.3-21.23",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_e_xml_developers_kit:21.3-21.23:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/21.3-21.23",
                                        "product": {
                                            "name": "Oracle Database Server(RDBMS) Version 21.3-21.23",
                                            "product_id": "P-5(RDBMS)V-21.3-21.23",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_rdbms:21.3-21.23:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/23.4.0-23.26.3",
                                        "product": {
                                            "name": "Oracle Database Server(Oracle Net Services) Version 23.4.0-23.26.3",
                                            "product_id": "P-5(Oracle Net Services)V-23.4.0-23.26.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_e_net_services:23.4.0-23.26.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/23.4.0-23.26.3",
                                        "product": {
                                            "name": "Oracle Database Server(Oracle Text) Version 23.4.0-23.26.3",
                                            "product_id": "P-5(Oracle Text)V-23.4.0-23.26.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_e_text:23.4.0-23.26.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/23.4.0-23.26.3",
                                        "product": {
                                            "name": "Oracle Database Server(Oracle XML Developers Kit) Version 23.4.0-23.26.3",
                                            "product_id": "P-5(Oracle XML Developers Kit)V-23.4.0-23.26.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_e_xml_developers_kit:23.4.0-23.26.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/23.4.0-23.26.3",
                                        "product": {
                                            "name": "Oracle Database Server(RDBMS) Version 23.4.0-23.26.3",
                                            "product_id": "P-5(RDBMS)V-23.4.0-23.26.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:database_-_rdbms:23.4.0-23.26.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Database Server"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Database Server"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Applications DBA Version 12.2.3-12.2.15",
                                            "product_id": "P-166V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:applications_dba:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Applications DBA"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Enterprise Command Center Framework Version V16",
                                        "product": {
                                            "name": "Enterprise Command Center Framework Version V16",
                                            "product_id": "P-13788V-V16",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:enterprise_command_center_framework:v16:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Enterprise Command Center Framework"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Advanced Benefits Version 12.2.3-12.2.15",
                                            "product_id": "P-290V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:advanced_benefits:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Advanced Benefits"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Alert Version 12.2.3-12.2.15",
                                            "product_id": "P-518V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:alert:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Alert"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Application Object Library Version 12.2.3-12.2.15",
                                            "product_id": "P-510V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:application_object_library:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Application Object Library"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Applications Framework Version 12.2.3-12.2.15",
                                            "product_id": "P-1472V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:applications_framework:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.9-12.2.15",
                                        "product": {
                                            "name": "Oracle Applications Framework Version 12.2.9-12.2.15",
                                            "product_id": "P-1472V-12.2.9-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:applications_framework:12.2.9-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Applications Framework"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Applications Manager Version 12.2.3-12.2.15",
                                            "product_id": "P-99V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:applications_manager:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Applications Manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Assets Version 12.2.3-12.2.15",
                                            "product_id": "P-503V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:assets:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Assets"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.13-12.2.15",
                                        "product": {
                                            "name": "Oracle Bills of Material Version 12.2.13-12.2.15",
                                            "product_id": "P-571V-12.2.13-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:bills_of_material:12.2.13-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Bills of Material Version 12.2.3-12.2.15",
                                            "product_id": "P-571V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:bills_of_material:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Bills of Material"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle CRM Technical Foundation Version 12.2.3-12.2.15",
                                            "product_id": "P-1199V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:crm_technical_foundation:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle CRM Technical Foundation"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Common Applications Version 12.2.3-12.2.15",
                                            "product_id": "P-1198V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:common_applications:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Common Applications"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Common Applications Calendar Version 12.2.3-12.2.15",
                                            "product_id": "P-1528V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:common_applications_calendar:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Common Applications Calendar"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.12-12.2.15",
                                        "product": {
                                            "name": "Oracle Complex Maintenance, Repair and Overhaul Version 12.2.12-12.2.15",
                                            "product_id": "P-1184V-12.2.12-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:complex_maintenance__repair_and_overhaul:12.2.12-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Complex Maintenance, Repair and Overhaul Version 12.2.3-12.2.15",
                                            "product_id": "P-1184V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:complex_maintenance__repair_and_overhaul:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Complex Maintenance, Repair and Overhaul"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.13-12.2.15",
                                        "product": {
                                            "name": "Oracle Contract Lifecycle Management for Public Sector Version 12.2.13-12.2.15",
                                            "product_id": "P-8759V-12.2.13-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:contract_lifecycle_management_for_public_sector:12.2.13-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Contract Lifecycle Management for Public Sector Version 12.2.3-12.2.15",
                                            "product_id": "P-8759V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:contract_lifecycle_management_for_public_sector:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.8-12.2.15",
                                        "product": {
                                            "name": "Oracle Contract Lifecycle Management for Public Sector Version 12.2.8-12.2.15",
                                            "product_id": "P-8759V-12.2.8-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:contract_lifecycle_management_for_public_sector:12.2.8-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Contract Lifecycle Management for Public Sector Version V16",
                                        "product": {
                                            "name": "Oracle Contract Lifecycle Management for Public Sector Version V16",
                                            "product_id": "P-8759V-V16",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:contract_lifecycle_management_for_public_sector:v16:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Contract Lifecycle Management for Public Sector"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.14-12.2.15",
                                        "product": {
                                            "name": "Oracle Contracts Version 12.2.14-12.2.15",
                                            "product_id": "P-154V-12.2.14-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:contracts:12.2.14-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Contracts"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Customer Interaction History Version 12.2.3-12.2.15",
                                            "product_id": "P-1374V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:customer_interaction_history:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Customer Interaction History"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Demand Signal Repository Version 12.2.3-12.2.15",
                                            "product_id": "P-4546V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:demand_signal_repository:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Demand Signal Repository"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.10-12.2.15",
                                        "product": {
                                            "name": "Oracle Depot Repair Version 12.2.10-12.2.15",
                                            "product_id": "P-516V-12.2.10-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:depot_repair:12.2.10-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Depot Repair Version 12.2.3-12.2.15",
                                            "product_id": "P-516V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:depot_repair:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Depot Repair"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Document Management and Collaboration Version 12.2.3-12.2.15",
                                            "product_id": "P-1314V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:document_management_and_collaboration:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Document Management and Collaboration"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Engineering Version 12.2.3-12.2.15",
                                            "product_id": "P-532V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:engineering:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Engineering"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Field Service Version 12.2.3-12.2.15",
                                            "product_id": "P-747V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:field_service:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Field Service"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Financials Common Modules Version 12.2.3-12.2.15",
                                            "product_id": "P-1320V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:financials_common_modules:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Financials Common Modules"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.8-12.2.15",
                                        "product": {
                                            "name": "Oracle Financials for Asia/Pacific Version 12.2.8-12.2.15",
                                            "product_id": "P-989V-12.2.8-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:financials_for_asia\\/pacific:12.2.8-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Financials for Asia/Pacific"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle HR Intelligence Version 12.2.3-12.2.15",
                                            "product_id": "P-33V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hr_intelligence:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle HR Intelligence"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle HRMS (India) Version 12.2.3-12.2.15",
                                            "product_id": "P-1557V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hrms:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle HRMS (India)"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Installed Base Version 12.2.3-12.2.15",
                                            "product_id": "P-1118V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:installed_base:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Installed Base"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.7-12.2.15",
                                        "product": {
                                            "name": "Oracle Lease and Finance Management Version 12.2.7-12.2.15",
                                            "product_id": "P-1056V-12.2.7-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:lease_and_finance_management:12.2.7-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Lease and Finance Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Marketing Version 12.2.3-12.2.15",
                                            "product_id": "P-229V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:marketing:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Marketing"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Mobile Application Server Version 12.2.3-12.2.15",
                                            "product_id": "P-995V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:mobile_application_server:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Mobile Application Server"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle One-to-One Fulfillment Version 12.2.3-12.2.15",
                                            "product_id": "P-1379V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:one-to-one_fulfillment:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle One-to-One Fulfillment"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.4-12.2.15",
                                        "product": {
                                            "name": "Oracle Order Management Version 12.2.4-12.2.15",
                                            "product_id": "P-497V-12.2.4-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:order_management:12.2.4-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.5-12.2.15",
                                        "product": {
                                            "name": "Oracle Order Management Version 12.2.5-12.2.15",
                                            "product_id": "P-497V-12.2.5-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:order_management:12.2.5-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Order Management Version V16",
                                        "product": {
                                            "name": "Oracle Order Management Version V16",
                                            "product_id": "P-497V-V16",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:order_management:v16:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Order Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Partner Management Version 12.2.3-12.2.15",
                                            "product_id": "P-1065V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:partner_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Partner Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Process Manufacturing Intelligence Version 12.2.3-12.2.15",
                                            "product_id": "P-23V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:process_manufacturing_intelligence:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Process Manufacturing Intelligence"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Product Hub Version 12.2.3-12.2.15",
                                            "product_id": "P-1313V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:product_hub:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Product Hub"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Product Workbench Version 12.2.3-12.2.15",
                                            "product_id": "P-1597V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:product_workbench:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Product Workbench"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Project Intelligence Version 12.2.3-12.2.15",
                                            "product_id": "P-1292V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:project_intelligence:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Project Intelligence"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Proposals Version 12.2.3-12.2.15",
                                            "product_id": "P-1333V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:proposals:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Proposals"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.10-12.2.15",
                                        "product": {
                                            "name": "Oracle Purchasing Version 12.2.10-12.2.15",
                                            "product_id": "P-502V-12.2.10-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:purchasing:12.2.10-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.11-12.2.15",
                                        "product": {
                                            "name": "Oracle Purchasing Version 12.2.11-12.2.15",
                                            "product_id": "P-502V-12.2.11-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:purchasing:12.2.11-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Purchasing Version 12.2.3-12.2.15",
                                            "product_id": "P-502V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:purchasing:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Purchasing"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Quality Version 12.2.3-12.2.15",
                                            "product_id": "P-214V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:quality:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Quality"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Report Manager Version 12.2.3-12.2.15",
                                            "product_id": "P-777V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:report_manager:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Report Manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Sales Version 12.2.3-12.2.15",
                                            "product_id": "P-1558V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:sales:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Sales"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Sales Offline Version 12.2.3-12.2.15",
                                            "product_id": "P-1009V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:sales_offline:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Sales Offline"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Sales Online Version 12.2.3-12.2.15",
                                            "product_id": "P-758V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:sales_online:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Sales Online"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Site Hub Version 12.2.3-12.2.15",
                                            "product_id": "P-1676V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:site_hub:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Site Hub"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Sourcing Version 12.2.3-12.2.15",
                                            "product_id": "P-1273V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:sourcing:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Sourcing"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Spares Management Version 12.2.3-12.2.15",
                                            "product_id": "P-754V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:spares_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Spares Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle US Federal Human Resources Version 12.2.3-12.2.15",
                                            "product_id": "P-899V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:us_federal_human_resources:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle US Federal Human Resources"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle User Management Version 12.2.3-12.2.15",
                                            "product_id": "P-1475V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:user_management:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.6-12.2.15",
                                        "product": {
                                            "name": "Oracle User Management Version 12.2.6-12.2.15",
                                            "product_id": "P-1475V-12.2.6-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:user_management:12.2.6-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle User Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Web Applications Desktop Integrator Version 12.2.3-12.2.15",
                                            "product_id": "P-1171V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:web_applications_desktop_integrator:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Web Applications Desktop Integrator"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle Work in Process Version 12.2.3-12.2.15",
                                            "product_id": "P-572V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:work_in_process:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Work in Process"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle XML Gateway Version 12.2.3-12.2.15",
                                            "product_id": "P-757V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:xml_gateway:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle XML Gateway"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle iRecruitment Version 12.2.3-12.2.15",
                                            "product_id": "P-1193V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:irecruitment:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle iRecruitment"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/12.2.3-12.2.15",
                                        "product": {
                                            "name": "Oracle iStore Version 12.2.3-12.2.15",
                                            "product_id": "P-384V-12.2.3-12.2.15",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:istore:12.2.3-12.2.15:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle iStore"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle E-Business Suite"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Enterprise Manager Base Platform Version 13.5",
                                        "product": {
                                            "name": "Oracle Enterprise Manager Base Platform Version 13.5",
                                            "product_id": "P-1370V-13.5",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:enterprise_manager_base_platform:13.5:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Enterprise Manager Base Platform Version 24.1",
                                        "product": {
                                            "name": "Oracle Enterprise Manager Base Platform Version 24.1",
                                            "product_id": "P-1370V-24.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:enterprise_manager_base_platform:24.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Enterprise Manager Base Platform"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Enterprise Manager for Fusion Middleware(Oracle Enterprise Manager for Fusion Middleware_Metrics) Version 13.5",
                                        "product": {
                                            "name": "Oracle Enterprise Manager for Fusion Middleware(Oracle Enterprise Manager for Fusion Middleware_Metrics) Version 13.5",
                                            "product_id": "P-1369(Oracle Enterprise Manager for Fusion Middleware_Metrics)V-13.5",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:enterprise_manager_for_fusion_middleware:13.5:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Enterprise Manager for Fusion Middleware(Oracle Enterprise Manager for Fusion Middleware_Metrics) Version 24.1",
                                        "product": {
                                            "name": "Oracle Enterprise Manager for Fusion Middleware(Oracle Enterprise Manager for Fusion Middleware_Metrics) Version 24.1",
                                            "product_id": "P-1369(Oracle Enterprise Manager for Fusion Middleware_Metrics)V-24.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:enterprise_manager_for_fusion_middleware:24.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Enterprise Manager for Fusion Middleware"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Enterprise Manager for Oracle Database Version 24.1",
                                        "product": {
                                            "name": "Oracle Enterprise Manager for Oracle Database Version 24.1",
                                            "product_id": "P-1366V-24.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:enterprise_manager_for_oracle_database:24.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Enterprise Manager for Oracle Database"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Enterprise Manager"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/14.5.0.0.0-14.9.0.0.0",
                                        "product": {
                                            "name": "Oracle Banking Branch Version 14.5.0.0.0-14.9.0.0.0",
                                            "product_id": "P-14324V-14.5.0.0.0-14.9.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:banking_branch:14.5.0.0.0-14.9.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Banking Branch"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/14.5.0.0.0-14.9.0.0.0",
                                        "product": {
                                            "name": "Oracle Banking Corporate Lending Version 14.5.0.0.0-14.9.0.0.0",
                                            "product_id": "P-12989V-14.5.0.0.0-14.9.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:banking_corporate_lending:14.5.0.0.0-14.9.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Banking Corporate Lending"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/14.5.0.0.0-14.9.0.0.0",
                                        "product": {
                                            "name": "Oracle Banking Corporate Lending Process Management Version 14.5.0.0.0-14.9.0.0.0",
                                            "product_id": "P-13701V-14.5.0.0.0-14.9.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.5.0.0.0-14.9.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Banking Corporate Lending Process Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/14.5.0.0.0-14.9.0.0.0",
                                        "product": {
                                            "name": "Oracle Banking Origination Version 14.5.0.0.0-14.9.0.0.0",
                                            "product_id": "P-14325V-14.5.0.0.0-14.9.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:banking_origination:14.5.0.0.0-14.9.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Banking Origination"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/14.5.0.0.0-14.9.0.0.0",
                                        "product": {
                                            "name": "Oracle Banking Treasury Management Version 14.5.0.0.0-14.9.0.0.0",
                                            "product_id": "P-14133V-14.5.0.0.0-14.9.0.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:banking_treasury_management:14.5.0.0.0-14.9.0.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Banking Treasury Management"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Financial Services Applications"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/3.0.0-3.2.20",
                                        "product": {
                                            "name": "Helidon Version 3.0.0-3.2.20",
                                            "product_id": "P-13972V-3.0.0-3.2.20",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:helidon:3.0.0-3.2.20:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/4.0.0-4.5.4",
                                        "product": {
                                            "name": "Helidon Version 4.0.0-4.5.4",
                                            "product_id": "P-13972V-4.0.0-4.5.4",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:helidon:4.0.0-4.5.4:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Helidon"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Access Manager Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Access Manager Version 12.2.1.4.0",
                                            "product_id": "P-5565V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:access_manager:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Access Manager Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Access Manager Version 14.1.2.0.0",
                                            "product_id": "P-5565V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:access_manager:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Access Manager Version 14.1.2.1.0",
                                        "product": {
                                            "name": "Oracle Access Manager Version 14.1.2.1.0",
                                            "product_id": "P-5565V-14.1.2.1.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:access_manager:14.1.2.1.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Access Manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Coherence Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Coherence Version 12.2.1.4.0",
                                            "product_id": "P-2545V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:coherence:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Coherence Version 14.1.1.0.0",
                                        "product": {
                                            "name": "Oracle Coherence Version 14.1.1.0.0",
                                            "product_id": "P-2545V-14.1.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:coherence:14.1.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Coherence Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Coherence Version 14.1.2.0.0",
                                            "product_id": "P-2545V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:coherence:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Coherence Version 15.1.1.0.0",
                                        "product": {
                                            "name": "Oracle Coherence Version 15.1.1.0.0",
                                            "product_id": "P-2545V-15.1.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:coherence:15.1.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Coherence"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Data Integrator Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Data Integrator Version 12.2.1.4.0",
                                            "product_id": "P-2196V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Data Integrator Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Data Integrator Version 14.1.2.0.0",
                                            "product_id": "P-2196V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:data_integrator:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Data Integrator"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Forms Version 12.2.1.19.0",
                                        "product": {
                                            "name": "Oracle Forms Version 12.2.1.19.0",
                                            "product_id": "P-45V-12.2.1.19.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:forms:12.2.1.19.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Forms Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Forms Version 14.1.2.0.0",
                                            "product_id": "P-45V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:forms:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Forms"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Fusion Middleware Control Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Fusion Middleware Control Version 12.2.1.4.0",
                                            "product_id": "P-14309V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:fusion_middleware_control:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Fusion Middleware Control Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Fusion Middleware Control Version 14.1.2.0.0",
                                            "product_id": "P-14309V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:fusion_middleware_control:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Fusion Middleware Control"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Identity Manager Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Identity Manager Version 12.2.1.4.0",
                                            "product_id": "P-1980V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:identity_manager:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Identity Manager Version 14.1.2.1.0",
                                        "product": {
                                            "name": "Oracle Identity Manager Version 14.1.2.1.0",
                                            "product_id": "P-1980V-14.1.2.1.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:identity_manager:14.1.2.1.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Identity Manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Identity Manager Connector Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Identity Manager Connector Version 12.2.1.4.0",
                                            "product_id": "P-1999V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:identity_manager_connector:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Identity Manager Connector Version 14.1.2.1.0",
                                        "product": {
                                            "name": "Oracle Identity Manager Connector Version 14.1.2.1.0",
                                            "product_id": "P-1999V-14.1.2.1.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:identity_manager_connector:14.1.2.1.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Identity Manager Connector"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Internet Directory Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Internet Directory Version 12.2.1.4.0",
                                            "product_id": "P-355V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:internet_directory:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Internet Directory Version 14.1.2.1.0",
                                        "product": {
                                            "name": "Oracle Internet Directory Version 14.1.2.1.0",
                                            "product_id": "P-355V-14.1.2.1.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:internet_directory:14.1.2.1.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Internet Directory"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle JDeveloper Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle JDeveloper Version 12.2.1.4.0",
                                            "product_id": "P-807V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:jdeveloper:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle JDeveloper Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle JDeveloper Version 14.1.2.0.0",
                                            "product_id": "P-807V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:jdeveloper:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle JDeveloper"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Managed File Transfer Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Managed File Transfer Version 12.2.1.4.0",
                                            "product_id": "P-10198V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:managed_file_transfer:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Managed File Transfer Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Managed File Transfer Version 14.1.2.0.0",
                                            "product_id": "P-10198V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:managed_file_transfer:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Managed File Transfer"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Middleware Common Libraries and Tools Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Middleware Common Libraries and Tools Version 12.2.1.4.0",
                                            "product_id": "P-4647V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Middleware Common Libraries and Tools Version 14.1.1.0.0",
                                        "product": {
                                            "name": "Oracle Middleware Common Libraries and Tools Version 14.1.1.0.0",
                                            "product_id": "P-4647V-14.1.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:middleware_common_libraries_and_tools:14.1.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Middleware Common Libraries and Tools Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Middleware Common Libraries and Tools Version 14.1.2.0.0",
                                            "product_id": "P-4647V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:middleware_common_libraries_and_tools:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Middleware Common Libraries and Tools Version 15.1.1.0.0",
                                        "product": {
                                            "name": "Oracle Middleware Common Libraries and Tools Version 15.1.1.0.0",
                                            "product_id": "P-4647V-15.1.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:middleware_common_libraries_and_tools:15.1.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Middleware Common Libraries and Tools"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Platform Security for Java Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Platform Security for Java Version 12.2.1.4.0",
                                            "product_id": "P-2233V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:platform_security_for_java:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Platform Security for Java Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Platform Security for Java Version 14.1.2.0.0",
                                            "product_id": "P-2233V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:platform_security_for_java:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Platform Security for Java"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Web Services Manager Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle Web Services Manager Version 12.2.1.4.0",
                                            "product_id": "P-1775V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:web_services_manager:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Web Services Manager Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle Web Services Manager Version 14.1.2.0.0",
                                            "product_id": "P-1775V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:web_services_manager:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Web Services Manager"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebCenter Content Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle WebCenter Content Version 12.2.1.4.0",
                                            "product_id": "P-2271V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:webcenter_content:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebCenter Content Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle WebCenter Content Version 14.1.2.0.0",
                                            "product_id": "P-2271V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:webcenter_content:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle WebCenter Content"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebCenter Enterprise Capture Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle WebCenter Enterprise Capture Version 12.2.1.4.0",
                                            "product_id": "P-10212V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:webcenter_enterprise_capture:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebCenter Enterprise Capture Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle WebCenter Enterprise Capture Version 14.1.2.0.0",
                                            "product_id": "P-10212V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:webcenter_enterprise_capture:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle WebCenter Enterprise Capture"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebCenter Portal Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle WebCenter Portal Version 12.2.1.4.0",
                                            "product_id": "P-1696V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebCenter Portal Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle WebCenter Portal Version 14.1.2.0.0",
                                            "product_id": "P-1696V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle WebCenter Portal"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebCenter Sites Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle WebCenter Sites Version 12.2.1.4.0",
                                            "product_id": "P-9617V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:webcenter_sites:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebCenter Sites Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle WebCenter Sites Version 14.1.2.0.0",
                                            "product_id": "P-9617V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:webcenter_sites:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle WebCenter Sites"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebLogic Server Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Oracle WebLogic Server Version 12.2.1.4.0",
                                            "product_id": "P-5242V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebLogic Server Version 14.1.1.0.0",
                                        "product": {
                                            "name": "Oracle WebLogic Server Version 14.1.1.0.0",
                                            "product_id": "P-5242V-14.1.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:weblogic_server:14.1.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebLogic Server Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Oracle WebLogic Server Version 14.1.2.0.0",
                                            "product_id": "P-5242V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:weblogic_server:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Oracle WebLogic Server Version 15.1.1.0.0",
                                        "product": {
                                            "name": "Oracle WebLogic Server Version 15.1.1.0.0",
                                            "product_id": "P-5242V-15.1.1.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:weblogic_server:15.1.1.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle WebLogic Server"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Service Delivery Platform Version 12.2.1.4.0",
                                        "product": {
                                            "name": "Service Delivery Platform Version 12.2.1.4.0",
                                            "product_id": "P-2063V-12.2.1.4.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:service_delivery_platform:12.2.1.4.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version",
                                        "name": "Service Delivery Platform Version 14.1.2.0.0",
                                        "product": {
                                            "name": "Service Delivery Platform Version 14.1.2.0.0",
                                            "product_id": "P-2063V-14.1.2.0.0",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:service_delivery_platform:14.1.2.0.0:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Service Delivery Platform"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Fusion Middleware"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Hyperion Data Relationship Management Version 11.2.26.0.000",
                                        "product": {
                                            "name": "Oracle Hyperion Data Relationship Management Version 11.2.26.0.000",
                                            "product_id": "P-4375V-11.2.26.0.000",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hyperion_data_relationship_management:11.2.26.0.000:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Hyperion Data Relationship Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Hyperion Financial Management Version 11.2.26.0.000",
                                        "product": {
                                            "name": "Oracle Hyperion Financial Management Version 11.2.26.0.000",
                                            "product_id": "P-4390V-11.2.26.0.000",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:hyperion_financial_management:11.2.26.0.000:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Hyperion Financial Management"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Hyperion"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle GraalVM Version 25.0.4.1",
                                        "product": {
                                            "name": "Oracle GraalVM Version 25.0.4.1",
                                            "product_id": "P-13497V-25.0.4.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:graalvm:25.0.4.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle GraalVM"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle GraalVM Enterprise Edition Version 21.3.19.1",
                                        "product": {
                                            "name": "Oracle GraalVM Enterprise Edition Version 21.3.19.1",
                                            "product_id": "P-13497V-21.3.19.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:graalvm:21.3.19.1:*:*:*:enterprise:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle GraalVM Enterprise Edition"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle GraalVM for JDK 17 Version 23.0.13.1",
                                        "product": {
                                            "name": "Oracle GraalVM for JDK 17 Version 23.0.13.1",
                                            "product_id": "P-13497V-23.0.13.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:graalvm_for_jdk_17:23.0.13.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle GraalVM for JDK 17"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle GraalVM for JDK 21 Version 23.1.12.1",
                                        "product": {
                                            "name": "Oracle GraalVM for JDK 21 Version 23.1.12.1",
                                            "product_id": "P-13497V-23.1.12.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:graalvm_for_jdk_21:23.1.12.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle GraalVM for JDK 21"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Java SE"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise CC Common Application Objects Version 9.2",
                                        "product": {
                                            "name": "PeopleSoft Enterprise CC Common Application Objects Version 9.2",
                                            "product_id": "P-8911V-9.2",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_cc_common_application_objects:9.2:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise CC Common Application Objects"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN Engineering Brazil Version 9.1",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN Engineering Brazil Version 9.1",
                                            "product_id": "P-4914V-9.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_engineering_brazil:9.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN Engineering Brazil"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise FIN Inventory Brazil Version 9.1",
                                        "product": {
                                            "name": "PeopleSoft Enterprise FIN Inventory Brazil Version 9.1",
                                            "product_id": "P-4998V-9.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_fin_inventory_brazil:9.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise FIN Inventory Brazil"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "PeopleSoft Enterprise PRTL Interaction Hub Version 9.1",
                                        "product": {
                                            "name": "PeopleSoft Enterprise PRTL Interaction Hub Version 9.1",
                                            "product_id": "P-5090V-9.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_prtl_interaction_hub:9.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise PRTL Interaction Hub"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/8.61-8.63",
                                        "product": {
                                            "name": "PeopleSoft Enterprise PeopleTools Version 8.61-8.63",
                                            "product_id": "P-5085V-8.61-8.63",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.61-8.63:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "PeopleSoft Enterprise PeopleTools"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle PeopleSoft"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/17.0-26.7",
                                        "product": {
                                            "name": "Siebel Apps - Customer Order Management Version 17.0-26.7",
                                            "product_id": "P-8967V-17.0-26.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_apps_-_customer_order_management:17.0-26.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Siebel Apps - Customer Order Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/17.0-26.7",
                                        "product": {
                                            "name": "Siebel Apps - Financial Services Version 17.0-26.7",
                                            "product_id": "P-9170V-17.0-26.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_apps_-_financial_services:17.0-26.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Siebel Apps - Financial Services"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/17.0-26.7",
                                        "product": {
                                            "name": "Siebel Apps - Life Sciences Version 17.0-26.7",
                                            "product_id": "P-9173V-17.0-26.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_apps_-_life_sciences:17.0-26.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Siebel Apps - Life Sciences"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/17.0-26.7",
                                        "product": {
                                            "name": "Siebel Apps - Marketing Version 17.0-26.7",
                                            "product_id": "P-8974V-17.0-26.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_apps_-_marketing:17.0-26.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Siebel Apps - Marketing"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/17.0-26.7",
                                        "product": {
                                            "name": "Siebel Apps - Self Service Version 17.0-26.7",
                                            "product_id": "P-8982V-17.0-26.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_apps_-_self_service:17.0-26.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Siebel Apps - Self Service"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/22.3-26.7",
                                        "product": {
                                            "name": "Siebel CRM Cloud Applications Version 22.3-26.7",
                                            "product_id": "P-14107V-22.3-26.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_cloud_applications:22.3-26.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Siebel CRM Cloud Applications"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/17.0-26.7",
                                        "product": {
                                            "name": "Siebel CRM Deployment Version 17.0-26.7",
                                            "product_id": "P-9019V-17.0-26.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_deployment:17.0-26.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/25.12-26.7",
                                        "product": {
                                            "name": "Siebel CRM Deployment Version 25.12-26.7",
                                            "product_id": "P-9019V-25.12-26.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_deployment:25.12-26.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Siebel CRM Deployment"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/17.0-26.7",
                                        "product": {
                                            "name": "Siebel CRM Development Version 17.0-26.7",
                                            "product_id": "P-9001V-17.0-26.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_development:17.0-26.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Siebel CRM Development"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/17.0-26.7",
                                        "product": {
                                            "name": "Siebel CRM End User Version 17.0-26.7",
                                            "product_id": "P-9011V-17.0-26.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_end_user:17.0-26.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Siebel CRM End User"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/17.0-26.7",
                                        "product": {
                                            "name": "Siebel CRM Integration Version 17.0-26.7",
                                            "product_id": "P-9008V-17.0-26.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_integration:17.0-26.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/23.6-26.7",
                                        "product": {
                                            "name": "Siebel CRM Integration Version 23.6-26.7",
                                            "product_id": "P-9008V-23.6-26.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_integration:23.6-26.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/25.12-26.7",
                                        "product": {
                                            "name": "Siebel CRM Integration Version 25.12-26.7",
                                            "product_id": "P-9008V-25.12-26.7",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:siebel_crm_integration:25.12-26.7:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Siebel CRM Integration"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Siebel CRM"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Agile Engineering Data Management Version 6.2.1",
                                        "product": {
                                            "name": "Oracle Agile Engineering Data Management Version 6.2.1",
                                            "product_id": "P-4436V-6.2.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Agile Engineering Data Management"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Agile PLM Version 9.3.6",
                                        "product": {
                                            "name": "Oracle Agile PLM Version 9.3.6",
                                            "product_id": "P-4461V-9.3.6",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Agile PLM"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Agile PLM MCAD Connector Version 3.6",
                                        "product": {
                                            "name": "Oracle Agile PLM MCAD Connector Version 3.6",
                                            "product_id": "P-4440V-3.6",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:agile_plm_mcad_connector:3.6:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Agile PLM MCAD Connector"
                            },
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle Product Lifecycle Analytics Version 3.6.1",
                                        "product": {
                                            "name": "Oracle Product Lifecycle Analytics Version 3.6.1",
                                            "product_id": "P-9387V-3.6.1",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Product Lifecycle Analytics"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Supply Chain"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/2.4.0.1.0-2.4.0.1.33",
                                        "product": {
                                            "name": "Oracle Utilities Network Management System Version 2.4.0.1.0-2.4.0.1.33",
                                            "product_id": "P-2241V-2.4.0.1.0-2.4.0.1.33",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.4.0.1.0-2.4.0.1.33:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/2.5.0.1.0-2.5.0.1.19",
                                        "product": {
                                            "name": "Oracle Utilities Network Management System Version 2.5.0.1.0-2.5.0.1.19",
                                            "product_id": "P-2241V-2.5.0.1.0-2.5.0.1.19",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.5.0.1.0-2.5.0.1.19:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/2.5.0.2.0-2.5.0.2.13",
                                        "product": {
                                            "name": "Oracle Utilities Network Management System Version 2.5.0.2.0-2.5.0.2.13",
                                            "product_id": "P-2241V-2.5.0.2.0-2.5.0.2.13",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.5.0.2.0-2.5.0.2.13:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/2.6.0.1.0-2.6.0.12B",
                                        "product": {
                                            "name": "Oracle Utilities Network Management System Version 2.6.0.1.0-2.6.0.12B",
                                            "product_id": "P-2241V-2.6.0.1.0-2.6.0.12B",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.6.0.1.0-2.6.0.12b:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/2.6.0.2.0-2.6.0.2.10A",
                                        "product": {
                                            "name": "Oracle Utilities Network Management System Version 2.6.0.2.0-2.6.0.2.10A",
                                            "product_id": "P-2241V-2.6.0.2.0-2.6.0.2.10A",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:2.6.0.2.0-2.6.0.2.10a:*:*:*:*:*:*:*"
                                            }
                                        }
                                    },
                                    {
                                        "category": "product_version_range",
                                        "name": "vers:semver/25.12.0.0.0-25.12.0.0.3",
                                        "product": {
                                            "name": "Oracle Utilities Network Management System Version 25.12.0.0.0-25.12.0.0.3",
                                            "product_id": "P-2241V-25.12.0.0.0-25.12.0.0.3",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:utilities_network_management_system:25.12.0.0.0-25.12.0.0.3:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle Utilities Network Management System"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Utilities Applications"
                    },
                    {
                        "branches": [
                            {
                                "branches": [
                                    {
                                        "category": "product_version",
                                        "name": "Oracle VM VirtualBox Version 7.2.16",
                                        "product": {
                                            "name": "Oracle VM VirtualBox Version 7.2.16",
                                            "product_id": "P-8370V-7.2.16",
                                            "product_identification_helper": {
                                                "cpe": "cpe:2.3:a:oracle:vm_virtualbox:7.2.16:*:*:*:*:*:*:*"
                                            }
                                        }
                                    }
                                ],
                                "category": "product_name",
                                "name": "Oracle VM VirtualBox"
                            }
                        ],
                        "category": "product_family",
                        "name": "Oracle Virtualization"
                    }
                ],
                "category": "vendor",
                "name": "Oracle"
            }
        ]
    },
    "vulnerabilities": [
        {
            "cve": "CVE-2023-48795",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39296038"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: File Processing (libssh2)).  Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSH to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61-8.63"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61-8.63"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU354"
                }
            ]
        },
        {
            "cve": "CVE-2023-6918",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39296038"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: File Processing (libssh2)).  Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSH to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61-8.63"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61-8.63"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU354"
                }
            ]
        },
        {
            "cve": "CVE-2025-68161",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39165057"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Treasury Management",
                    "text": "39398910"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Diagnostic Kit (Apache Log4j)).  Supported versions that are affected are 13.5 and  24.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Enterprise Manager Base Platform accessible data as well as  unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Treasury Management product of Oracle Financial Services Applications (component: Infrastructure (Apache Log4j)).  Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Treasury Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Treasury Management accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-14133V-14.5.0.0.0-14.9.0.0.0",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU350"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14133V-14.5.0.0.0-14.9.0.0.0"
                    ],
                    "url": "https://support.oracle.com"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-0540",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
                    "text": "39722866"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (DOMPurify)).   The supported version that is affected is 6.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Operations Monitor accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Operations Monitor accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10761V-6.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10761V-6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU347"
                }
            ]
        },
        {
            "cve": "CVE-2026-10803",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39874672"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MLflow)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-10879",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39868962"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (DBI)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-12590",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39869069"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Node.js)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.7,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-13006",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39848192"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (logback)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.0,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-13346",
            "flags": [
                {
                    "date": "2026-09-15T13:00:00-07:00",
                    "label": "vulnerable_code_cannot_be_controlled_by_adversary",
                    "product_ids": [
                        "P-14634V-26.3.1",
                        "P-14634V-26.8",
                        "P-14634V-26.5.3",
                        "P-14634V-26.2"
                    ]
                }
            ],
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Autonomous Health Framework",
                    "text": "39924720"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle Autonomous Health Framework (component: CLISDK (pip)). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-14634V-26.3.1",
                    "P-14634V-26.2",
                    "P-14634V-26.8",
                    "P-14634V-26.5.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14634V-26.3.1",
                        "P-14634V-26.8",
                        "P-14634V-26.5.3",
                        "P-14634V-26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU345"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14634V-26.3.1",
                        "P-14634V-26.8",
                        "P-14634V-26.5.3",
                        "P-14634V-26.2"
                    ]
                }
            ],
            "threats": [
                {
                    "category": "impact",
                    "date": "2026-09-15T13:00:00-07:00",
                    "details": "The vulnerable component is present, and the component contains the vulnerable code. However, vulnerable code is used in such a way that an attacker cannot mount any anticipated attack.",
                    "product_ids": [
                        "P-14634V-26.3.1",
                        "P-14634V-26.8",
                        "P-14634V-26.5.3",
                        "P-14634V-26.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-13484",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39874672"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MLflow)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-13706",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-13707",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-13758",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39928934"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (CryptX)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 3.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.7,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-14358",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-14363",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-14380",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39868962"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (DBI)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-14456",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Autonomous Health Framework",
                    "text": "39955339"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Autonomous Health Framework (component: AHFCOMMON (OpenSSL)).  Supported versions that are affected are 26.2, 26.3.1, 26.5.3 and  26.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Autonomous Health Framework.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Autonomous Health Framework. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14634V-26.3.1",
                    "P-14634V-26.2",
                    "P-14634V-26.8",
                    "P-14634V-26.5.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14634V-26.3.1",
                        "P-14634V-26.8",
                        "P-14634V-26.5.3",
                        "P-14634V-26.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU345"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14634V-26.3.1",
                        "P-14634V-26.8",
                        "P-14634V-26.5.3",
                        "P-14634V-26.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-14739",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39868962"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (DBI)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-14740",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39868962"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (DBI)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-17544",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39840347"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (PHP)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-19880",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39902525"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (logback)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-2332",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39565222"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: OMS (Eclipse Jetty)).   The supported version that is affected is 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data as well as  unauthorized access to critical data or complete access to all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU350"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-25639",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise CC Common Application Objects",
                    "text": "39089657"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise CC Common Application Objects product of Oracle PeopleSoft (component: Chatbot Framework (Axios)).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CC Common Application Objects.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise CC Common Application Objects. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8911V-9.2"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8911V-9.2"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU354"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8911V-9.2"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-3198",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39874672"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MLflow)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-34477",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications MetaSolv Solution Module - ASR",
                    "text": "39939725"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Treasury Management",
                    "text": "39398910"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Treasury Management product of Oracle Financial Services Applications (component: Infrastructure (Apache Log4j)).  Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Treasury Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Treasury Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications MetaSolv Solution Module - ASR product of Oracle Communications (component: Access Service Request (Apache Log4j)).   The supported version that is affected is 70.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Communications MetaSolv Solution Module - ASR.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications MetaSolv Solution Module - ASR accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14133V-14.5.0.0.0-14.9.0.0.0",
                    "P-2281V-70.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14133V-14.5.0.0.0-14.9.0.0.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2281V-70.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU358"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2281V-70.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-34478",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications MetaSolv Solution Module - ASR",
                    "text": "39939725"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Treasury Management",
                    "text": "39398910"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Treasury Management product of Oracle Financial Services Applications (component: Infrastructure (Apache Log4j)).  Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Treasury Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Treasury Management accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications MetaSolv Solution Module - ASR product of Oracle Communications (component: Access Service Request (Apache Log4j)).   The supported version that is affected is 70.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Communications MetaSolv Solution Module - ASR.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications MetaSolv Solution Module - ASR accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14133V-14.5.0.0.0-14.9.0.0.0",
                    "P-2281V-70.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14133V-14.5.0.0.0-14.9.0.0.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2281V-70.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU358"
                }
            ]
        },
        {
            "cve": "CVE-2026-34479",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Treasury Management",
                    "text": "39398910"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Treasury Management product of Oracle Financial Services Applications (component: Infrastructure (Apache Log4j)).  Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Treasury Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Treasury Management accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14133V-14.5.0.0.0-14.9.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14133V-14.5.0.0.0-14.9.0.0.0"
                    ],
                    "url": "https://support.oracle.com"
                }
            ]
        },
        {
            "cve": "CVE-2026-34480",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications MetaSolv Solution Module - ASR",
                    "text": "39939725"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Treasury Management",
                    "text": "39398910"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Treasury Management product of Oracle Financial Services Applications (component: Infrastructure (Apache Log4j)).  Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Banking Treasury Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Treasury Management accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications MetaSolv Solution Module - ASR product of Oracle Communications (component: Access Service Request (Apache Log4j)).   The supported version that is affected is 70.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Communications MetaSolv Solution Module - ASR.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications MetaSolv Solution Module - ASR accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14133V-14.5.0.0.0-14.9.0.0.0",
                    "P-2281V-70.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14133V-14.5.0.0.0-14.9.0.0.0"
                    ],
                    "url": "https://support.oracle.com"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2281V-70.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU358"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14133V-14.5.0.0.0-14.9.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-39822",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39867447"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Golang Go)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-4035",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39874672"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MLflow)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-41238",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
                    "text": "39722866"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (DOMPurify)).   The supported version that is affected is 6.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Operations Monitor accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Operations Monitor accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10761V-6.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10761V-6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU347"
                }
            ]
        },
        {
            "cve": "CVE-2026-41239",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
                    "text": "39722866"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (DOMPurify)).   The supported version that is affected is 6.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Operations Monitor accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Operations Monitor accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10761V-6.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10761V-6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU347"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10761V-6.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-41240",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Operations Monitor",
                    "text": "39722866"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Operations Monitor product of Oracle Communications (component: Mediation Engine (DOMPurify)).   The supported version that is affected is 6.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Operations Monitor.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Operations Monitor accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Operations Monitor accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10761V-6.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10761V-6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU347"
                }
            ]
        },
        {
            "cve": "CVE-2026-41409",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39663921"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen (Apache Mina)).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU350"
                }
            ]
        },
        {
            "cve": "CVE-2026-41635",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39663921"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen (Apache Mina)).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU350"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-41989",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39399862"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (libgcrypt)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.7 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-41990",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39399862"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (libgcrypt)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-42505",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39867447"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Golang Go)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Communications Unified Assurance executes to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-42779",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39663921"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Agent Next Gen (Apache Mina)).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager Base Platform.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU350"
                }
            ]
        },
        {
            "cve": "CVE-2026-44024",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39875962"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Fluentd)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-44025",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39875962"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Fluentd)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-44160",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39875962"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Fluentd)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-44161",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39875962"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Fluentd)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-44249",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39646610"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39830859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration (Netty)).  Supported versions that are affected are 25.12-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Third Party Patch (Netty)).  Supported versions that are affected are 8.0-8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-25.12-26.7",
                    "P-2283V-8.0-8.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-25.12-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0-8.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU344"
                }
            ]
        },
        {
            "cve": "CVE-2026-45416",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39646610"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39830859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration (Netty)).  Supported versions that are affected are 25.12-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Third Party Patch (Netty)).  Supported versions that are affected are 8.0-8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-25.12-26.7",
                    "P-2283V-8.0-8.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-25.12-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0-8.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU344"
                }
            ]
        },
        {
            "cve": "CVE-2026-45536",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39646610"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration (Netty)).  Supported versions that are affected are 25.12-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-25.12-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-25.12-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ]
        },
        {
            "cve": "CVE-2026-45673",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39830859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Third Party Patch (Netty)).  Supported versions that are affected are 8.0-8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2283V-8.0-8.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0-8.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU344"
                }
            ]
        },
        {
            "cve": "CVE-2026-45674",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39830859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Third Party Patch (Netty)).  Supported versions that are affected are 8.0-8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2283V-8.0-8.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0-8.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU344"
                }
            ]
        },
        {
            "cve": "CVE-2026-46936",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-47012",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-47023",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-47052",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-47064",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-47065",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39736050"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Third Party (Apache Mina)).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP/IP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-47691",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39830859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Third Party Patch (Netty)).  Supported versions that are affected are 8.0-8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2283V-8.0-8.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0-8.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU344"
                }
            ]
        },
        {
            "cve": "CVE-2026-48855",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39876103"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Erlang/OTP)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-48856",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39876103"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Erlang/OTP)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-48858",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39876103"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Erlang/OTP)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-48860",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39876103"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Erlang/OTP)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-48998",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39880413"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Guzzle PSR-7)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-49214",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39880413"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Guzzle PSR-7)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-49284",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39862767"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (SimpleSAMLphp)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-49759",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39876103"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Erlang/OTP)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-49760",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39876103"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Erlang/OTP)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-49844",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39778983"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39776269"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: OMS (Apache Log4j)).  Supported versions that are affected are 13.5 and  24.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Log4j)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 5.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-24.1",
                    "P-1370V-13.5",
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU350"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.9,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5",
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-50010",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39646610"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39830859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration (Netty)).  Supported versions that are affected are 25.12-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Third Party Patch (Netty)).  Supported versions that are affected are 8.0-8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-25.12-26.7",
                    "P-2283V-8.0-8.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-25.12-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0-8.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU344"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9008V-25.12-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-50020",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39830859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Third Party Patch (Netty)).  Supported versions that are affected are 8.0-8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2283V-8.0-8.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0-8.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU344"
                }
            ]
        },
        {
            "cve": "CVE-2026-50229",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39705180"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI (Apache Tomcat)).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data as well as  unauthorized read access to a subset of Siebel CRM Integration accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ]
        },
        {
            "cve": "CVE-2026-50734",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39840899"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Message Bus (Apache ActiveMQ)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-53404",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39705180"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI (Apache Tomcat)).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data as well as  unauthorized read access to a subset of Siebel CRM Integration accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ]
        },
        {
            "cve": "CVE-2026-53422",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39876103"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Erlang/OTP)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-53434",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39705180"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI (Apache Tomcat)).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data as well as  unauthorized read access to a subset of Siebel CRM Integration accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ]
        },
        {
            "cve": "CVE-2026-54512",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39646386"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39868163"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39663712"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration (jackson-databind)).  Supported versions that are affected are 25.12-26.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Database Upgrade (jackson-databind)).  Supported versions that are affected are 25.12-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (jackson-databind)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-25.12-26.7",
                    "P-14597V-6.1.1-7.0.0",
                    "P-9008V-25.12-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-25.12-26.7",
                        "P-9008V-25.12-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-54513",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39646386"
                },
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39868163"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39663712"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration (jackson-databind)).  Supported versions that are affected are 25.12-26.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Database Upgrade (jackson-databind)).  Supported versions that are affected are 25.12-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (jackson-databind)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-25.12-26.7",
                    "P-14597V-6.1.1-7.0.0",
                    "P-9008V-25.12-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-25.12-26.7",
                        "P-9008V-25.12-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9008V-25.12-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-54514",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39868163"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39663712"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Database Upgrade (jackson-databind)).  Supported versions that are affected are 25.12-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data.",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (jackson-databind)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-25.12-26.7",
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-25.12-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-54515",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39868163"
                },
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39663712"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Database Upgrade (jackson-databind)).  Supported versions that are affected are 25.12-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                },
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (jackson-databind)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-25.12-26.7",
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-25.12-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                },
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-25.12-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-54516",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39868163"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (jackson-databind)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-54517",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39868163"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (jackson-databind)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-54518",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39868163"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (jackson-databind)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-54886",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39876103"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Erlang/OTP)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-54887",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39876103"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Erlang/OTP)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-55276",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39705180"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI (Apache Tomcat)).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data as well as  unauthorized read access to a subset of Siebel CRM Integration accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ]
        },
        {
            "cve": "CVE-2026-55554",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39862875"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Dompdf)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-55555",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39862875"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Dompdf)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-55568",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879701"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Guzzle)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-55766",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39880413"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Guzzle PSR-7)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-55767",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879701"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Guzzle)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-55831",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39830859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Third Party Patch (Netty)).  Supported versions that are affected are 8.0-8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2283V-8.0-8.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0-8.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU344"
                }
            ]
        },
        {
            "cve": "CVE-2026-55833",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39830859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Third Party Patch (Netty)).  Supported versions that are affected are 8.0-8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2283V-8.0-8.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0-8.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU344"
                }
            ]
        },
        {
            "cve": "CVE-2026-55950",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39876103"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Erlang/OTP)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-55952",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39876103"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Erlang/OTP)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-55955",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39705180"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI (Apache Tomcat)).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data as well as  unauthorized read access to a subset of Siebel CRM Integration accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ]
        },
        {
            "cve": "CVE-2026-55956",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39705180"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI (Apache Tomcat)).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data as well as  unauthorized read access to a subset of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9008V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-56722",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39862875"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Dompdf)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-56745",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39830859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Third Party Patch (Netty)).  Supported versions that are affected are 8.0-8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2283V-8.0-8.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0-8.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU344"
                }
            ]
        },
        {
            "cve": "CVE-2026-56746",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39830859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Third Party Patch (Netty)).  Supported versions that are affected are 8.0-8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2283V-8.0-8.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0-8.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU344"
                }
            ]
        },
        {
            "cve": "CVE-2026-57211",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39861530"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Message Bus (Pivotal RabbitMQ)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-57212",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39861530"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Message Bus (Pivotal RabbitMQ)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-57213",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39861530"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Message Bus (Pivotal RabbitMQ)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-57214",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39861530"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Message Bus (Pivotal RabbitMQ)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-57215",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39861530"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Message Bus (Pivotal RabbitMQ)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-57216",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39861530"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Message Bus (Pivotal RabbitMQ)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-57217",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39861530"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Message Bus (Pivotal RabbitMQ)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-57218",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39861530"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Message Bus (Pivotal RabbitMQ)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-57219",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39861530"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Message Bus (Pivotal RabbitMQ)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-57220",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39861530"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Message Bus (Pivotal RabbitMQ)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-57221",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39861530"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Message Bus (Pivotal RabbitMQ)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-58024",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-58025",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-58026",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-58027",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-58028",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-58029",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-58030",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-58032",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-58033",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-58037",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-58038",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-58517",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-58520",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-58521",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-59882",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39880413"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Guzzle PSR-7)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-59883",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879701"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Guzzle)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-59898",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39830859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Third Party Patch (Netty)).  Supported versions that are affected are 8.0-8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2283V-8.0-8.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0-8.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU344"
                }
            ]
        },
        {
            "cve": "CVE-2026-59899",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39830859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Third Party Patch (Netty)).  Supported versions that are affected are 8.0-8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2283V-8.0-8.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0-8.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU344"
                }
            ]
        },
        {
            "cve": "CVE-2026-59901",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39830859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Third Party Patch (Netty)).  Supported versions that are affected are 8.0-8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2283V-8.0-8.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0-8.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU344"
                }
            ]
        },
        {
            "cve": "CVE-2026-59921",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39830859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Third Party Patch (Netty)).  Supported versions that are affected are 8.0-8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2283V-8.0-8.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0-8.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU344"
                }
            ]
        },
        {
            "cve": "CVE-2026-59941",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39862875"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Dompdf)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-59942",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39862875"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Dompdf)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-59943",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39862875"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Dompdf)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-60145",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60163",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60177",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60178",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60182",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60183",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60184",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60185",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60186",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60187",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60188",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60189",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60190",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60191",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60315",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60316",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60331",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60332",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60585",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-60747",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-61081",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-61094",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-61096",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-61109",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MySQL Server)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-61308",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Autonomous Health Framework",
                    "text": "39981285"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Security-in-Depth issue in Oracle Autonomous Health Framework (component: AHFCOMMON). This vulnerability cannot be exploited in the context of this product.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_not_affected": [
                    "P-14634V-26.8"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14634V-26.8"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU345"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 0.0,
                        "baseSeverity": "NONE",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14634V-26.8"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-62597",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager Base Platform",
                    "text": "39364129"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data. CVSS 3.1 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1370V-13.5",
                    "P-1370V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU350"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1370V-24.1",
                        "P-1370V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-63308",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39862151"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Helm)).   The supported version that is affected is 7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-64849",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39874672"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MLflow)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-66299",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39832448"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache Tomcat)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-67339",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879701"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Guzzle)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-67353",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879701"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Guzzle)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-67354",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879701"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Guzzle)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-67355",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879701"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Guzzle)).  Supported versions that are affected are 6.1.1-7.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-69146",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39874672"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MLflow)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-69148",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39874672"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MLflow)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-70748",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39924025"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Polina Demura"
                    ]
                }
            ],
            "cve": "CVE-2026-70755",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Web Applications Desktop Integrator",
                    "text": "39115858"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Web Applications Desktop Integrator accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1171V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1171V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1171V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-70756",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39213031"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-70757",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39263694"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-70913",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39271524"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1980V-12.2.1.4.0",
                    "P-1980V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-70915",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39271547"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1980V-12.2.1.4.0",
                    "P-1980V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-71047",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39271559"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1980V-12.2.1.4.0",
                    "P-1980V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-71133",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39272797"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 10.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-71163",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39272799"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager.  While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Access Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Access Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Access Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-71290",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39873672"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (Apache HttpClient)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73193",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39868962"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (DBI)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-73194",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39868962"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (DBI)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14597V-6.1.1-7.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73508",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39830859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Third Party Patch (Netty)).  Supported versions that are affected are 8.0-8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2283V-8.0-8.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0-8.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU344"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2283V-8.0-8.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73926",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39272806"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Access Manager.  While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Access Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73940",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39272832"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73941",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39272835"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73942",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39272851"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1980V-12.2.1.4.0",
                    "P-1980V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73943",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39275761"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Identity Manager.  While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data as well as  unauthorized update, insert or delete access to some of Oracle Identity Manager accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1980V-12.2.1.4.0",
                    "P-1980V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73944",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39284182"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Access Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73945",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39284185"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager.  While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73946",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39284201"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Access Manager.  While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73947",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39284212"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-12.2.1.4.0",
                    "P-5565V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-12.2.1.4.0",
                        "P-5565V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-12.2.1.4.0",
                        "P-5565V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73948",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39284261"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73949",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39284263"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73950",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39272814"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73951",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39284270"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73952",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39284274"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73953",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39284275"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73954",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39288854"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink).  Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61-8.63"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61-8.63"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU354"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61-8.63"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73955",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39296076"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Charting).  Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61-8.63"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61-8.63"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU354"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61-8.63"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73956",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39284287"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73957",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39284288"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.3,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73958",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39284931"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-12.2.1.4.0",
                    "P-5565V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-12.2.1.4.0",
                        "P-5565V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-12.2.1.4.0",
                        "P-5565V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73959",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39284953"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73960",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39297539"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Ren Server).  Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61-8.63"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61-8.63"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU354"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61-8.63"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73961",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle JDeveloper",
                    "text": "39286439"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Faces).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-807V-14.1.2.0.0",
                    "P-807V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73962",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39286781"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Access Manager.  While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Access Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Access Manager accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.6,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73963",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39286827"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73965",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39288498"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Cloud Gateway).  Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Deployment accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-73966",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel Apps - Marketing",
                    "text": "39288502"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel Apps - Marketing product of Oracle Siebel CRM (component: Marketing).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel Apps - Marketing.  Successful attacks of this vulnerability can result in takeover of Siebel Apps - Marketing. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8974V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8974V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8974V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-75838",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Autonomous Health Framework",
                    "text": "39962146"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Autonomous Health Framework (component: AHFCOMMON (DOMPurify)).   The supported version that is affected is 26.8. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Autonomous Health Framework.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Autonomous Health Framework accessible data as well as  unauthorized read access to a subset of Oracle Autonomous Health Framework accessible data. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14634V-26.8"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14634V-26.8"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU345"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.6,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14634V-26.8"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-7598",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39296038"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: File Processing (libssh2)).  Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSH to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61-8.63"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61-8.63"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU354"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61-8.63"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-8147",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39874672"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MLflow)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Unified Assurance accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-82992",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39288818"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Installation).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-82993",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39288856"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Business Interlink).  Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61-8.63"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61-8.63"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU354"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61-8.63"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-82994",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Platform Security for Java",
                    "text": "39289014"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Platform Security for Java.  Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2233V-14.1.2.0.0",
                    "P-2233V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-82995",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Platform Security for Java",
                    "text": "39289033"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Platform Security for Java.  Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2233V-14.1.2.0.0",
                    "P-2233V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-82996",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Platform Security for Java",
                    "text": "39289038"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Platform Security for Java executes to compromise Oracle Platform Security for Java.  Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2233V-14.1.2.0.0",
                    "P-2233V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-82997",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289348"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery Platform.  While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-82998",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289356"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Service Delivery Platform.  While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-82999",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289360"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Service Delivery Platform.  While the vulnerability is in Service Delivery Platform, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83000",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39289410"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Service Delivery Platform.  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83001",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39292473"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Access Manager.  While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83002",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39292476"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager.  While the vulnerability is in Oracle Access Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Access Manager. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83003",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39293387"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle WebCenter Enterprise Capture.  While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Enterprise Capture accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Enterprise Capture accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83004",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39293392"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebCenter Enterprise Capture executes to compromise Oracle WebCenter Enterprise Capture.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Enterprise Capture accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebCenter Enterprise Capture accessible data. CVSS 3.1 Base Score 7.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83005",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39293393"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83006",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39293397"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture.  While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83007",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39293398"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture.  While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Enterprise Capture accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Enterprise Capture accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83008",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39293399"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle WebCenter Enterprise Capture.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83009",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39293857"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83010",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39293865"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Enterprise Capture accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebCenter Enterprise Capture accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83011",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Platform Security for Java",
                    "text": "39295112"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java.  Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2233V-14.1.2.0.0",
                    "P-2233V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83012",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39295147"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture.  While the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Enterprise Capture accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83013",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39295152"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83014",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39296172"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager).  Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61-8.63"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61-8.63"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU354"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61-8.63"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83015",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39296220"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Cube Manager).  Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61-8.63"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61-8.63"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU354"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61-8.63"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83016",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39296272"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR).  Supported versions that are affected are 8.61-8.63. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61-8.63"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61-8.63"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU354"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61-8.63"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83017",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39296287"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Report Distribution).  Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61-8.63"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61-8.63"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU354"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61-8.63"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83018",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39296298"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR).  Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise PeopleTools executes to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61-8.63"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61-8.63"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU354"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61-8.63"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83019",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39296303"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: SQR).  Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.1 Base Score 8.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61-8.63"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61-8.63"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU354"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61-8.63"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83020",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Platform Security for Java",
                    "text": "39296999"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Platform Security for Java.  While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2233V-14.1.2.0.0",
                    "P-2233V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 10.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2233V-12.2.1.4.0",
                        "P-2233V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83021",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39297038"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 10.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83022",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39297062"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle WebCenter Enterprise Capture executes to compromise Oracle WebCenter Enterprise Capture.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Enterprise Capture, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 7.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.9,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83023",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager Connector",
                    "text": "39299883"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager Connector.  While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1999V-12.2.1.4.0",
                    "P-1999V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83024",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager Connector",
                    "text": "39299887"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1999V-12.2.1.4.0",
                    "P-1999V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83025",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager Connector",
                    "text": "39299889"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Identity Manager Connector.  While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data as well as  unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1999V-12.2.1.4.0",
                    "P-1999V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83026",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager Connector",
                    "text": "39299891"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector.  While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1999V-12.2.1.4.0",
                    "P-1999V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83027",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager Connector",
                    "text": "39299892"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector.  While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager Connector accessible data as well as  unauthorized access to critical data or complete access to all Oracle Identity Manager Connector accessible data. CVSS 3.1 Base Score 9.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1999V-12.2.1.4.0",
                    "P-1999V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.3,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83028",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager Connector",
                    "text": "39299894"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Identity Manager Connector executes to compromise Oracle Identity Manager Connector.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1999V-12.2.1.4.0",
                    "P-1999V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83029",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Managed File Transfer",
                    "text": "39300068"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Managed File Transfer.  While the vulnerability is in Oracle Managed File Transfer, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Managed File Transfer accessible data as well as  unauthorized access to critical data or complete access to all Oracle Managed File Transfer accessible data. CVSS 3.1 Base Score 9.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10198V-14.1.2.0.0",
                    "P-10198V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10198V-14.1.2.0.0",
                        "P-10198V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.6,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10198V-14.1.2.0.0",
                        "P-10198V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83030",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Managed File Transfer",
                    "text": "39300075"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middleware (component: MFT Runtime Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via T3, IIOP to compromise Oracle Managed File Transfer.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Managed File Transfer accessible data as well as  unauthorized read access to a subset of Oracle Managed File Transfer accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Managed File Transfer. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10198V-14.1.2.0.0",
                    "P-10198V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10198V-14.1.2.0.0",
                        "P-10198V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10198V-14.1.2.0.0",
                        "P-10198V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83031",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
                    "text": "39300107"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites.  While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9617V-12.2.1.4.0",
                    "P-9617V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83032",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
                    "text": "39300108"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9617V-12.2.1.4.0",
                    "P-9617V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83033",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
                    "text": "39300110"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9617V-12.2.1.4.0",
                    "P-9617V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83034",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
                    "text": "39300119"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9617V-12.2.1.4.0",
                    "P-9617V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83035",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
                    "text": "39300125"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9617V-12.2.1.4.0",
                    "P-9617V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83036",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
                    "text": "39300127"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9617V-12.2.1.4.0",
                    "P-9617V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83037",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Sites",
                    "text": "39300129"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9617V-12.2.1.4.0",
                    "P-9617V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9617V-12.2.1.4.0",
                        "P-9617V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83038",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebLogic Server",
                    "text": "39300401"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: TopLink Integration).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebLogic Server.  While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5242V-15.1.1.0.0",
                    "P-5242V-12.2.1.4.0",
                    "P-5242V-14.1.2.0.0",
                    "P-5242V-14.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5242V-15.1.1.0.0",
                        "P-5242V-14.1.1.0.0",
                        "P-5242V-12.2.1.4.0",
                        "P-5242V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83039",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39300421"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83040",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39300424"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle WebCenter Portal.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.6,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83041",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39300427"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Portlet Services).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83042",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39301044"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1980V-12.2.1.4.0",
                    "P-1980V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83043",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301061"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.6,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83044",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle XML Gateway",
                    "text": "39310517"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle XML Gateway.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle XML Gateway. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-757V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-757V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-757V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83045",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301085"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83046",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301093"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83047",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301095"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83048",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301111"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83049",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301114"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Security Framework).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83050",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301119"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83051",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301152"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83052",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301166"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Portal accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Portal accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83053",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301177"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83054",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Internet Directory",
                    "text": "39301243"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.  Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-355V-12.2.1.4.0",
                    "P-355V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83055",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Internet Directory",
                    "text": "39301247"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory.  While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-355V-12.2.1.4.0",
                    "P-355V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83056",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Internet Directory",
                    "text": "39301248"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory.  While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-355V-12.2.1.4.0",
                    "P-355V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83057",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Internet Directory",
                    "text": "39301250"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory.  While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-355V-12.2.1.4.0",
                    "P-355V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83058",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Internet Directory",
                    "text": "39301258"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle Internet Directory.  While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-355V-12.2.1.4.0",
                    "P-355V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83059",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Internet Directory",
                    "text": "39301260"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.  While the vulnerability is in Oracle Internet Directory, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-355V-12.2.1.4.0",
                    "P-355V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 10.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83060",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Internet Directory",
                    "text": "39301271"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.  Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-355V-12.2.1.4.0",
                    "P-355V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83061",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Internet Directory",
                    "text": "39301273"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.  Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-355V-12.2.1.4.0",
                    "P-355V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83062",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Internet Directory",
                    "text": "39301277"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via LDAP to compromise Oracle Internet Directory.  Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-355V-12.2.1.4.0",
                    "P-355V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83063",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Internet Directory",
                    "text": "39301290"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via LDAP to compromise Oracle Internet Directory.  Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-355V-12.2.1.4.0",
                    "P-355V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83064",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301301"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal.  While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0",
                    "P-1696V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0",
                        "P-1696V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83065",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Portal",
                    "text": "39301370"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools).   The supported version that is affected is 14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle WebCenter Portal executes to compromise Oracle WebCenter Portal.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1696V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1696V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1696V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83066",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Internet Directory",
                    "text": "39301631"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to compromise Oracle Internet Directory.  Successful attacks of this vulnerability can result in takeover of Oracle Internet Directory. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-355V-12.2.1.4.0",
                    "P-355V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-355V-12.2.1.4.0",
                        "P-355V-14.1.2.1.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83067",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle JDeveloper",
                    "text": "39326386"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: ADF Shared Components).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle JDeveloper accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle JDeveloper. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-807V-14.1.2.0.0",
                    "P-807V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83068",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager for Oracle Database",
                    "text": "39336384"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: Core).   The supported version that is affected is 24.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Enterprise Manager for Oracle Database.  While the vulnerability is in Oracle Enterprise Manager for Oracle Database, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Enterprise Manager for Oracle Database accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1366V-24.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1366V-24.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU350"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1366V-24.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83069",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Fusion Middleware Control",
                    "text": "39344127"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Fusion Middleware Control product of Oracle Fusion Middleware (component: Framework).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Fusion Middleware Control.  Successful attacks of this vulnerability can result in takeover of Oracle Fusion Middleware Control. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14309V-12.2.1.4.0",
                    "P-14309V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14309V-12.2.1.4.0",
                        "P-14309V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14309V-12.2.1.4.0",
                        "P-14309V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83070",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PRTL Interaction Hub",
                    "text": "39349017"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub product of Oracle PeopleSoft (component: Enterprise Portal).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub.  While the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5090V-9.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5090V-9.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU354"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5090V-9.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83071",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39350668"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Machine Learning).  Supported versions that are affected are 8.2.0.0.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83072",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Framework",
                    "text": "39351717"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Search Bean [Incl.  Advanced]).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Applications Framework accessible data as well as  unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1472V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1472V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1472V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83073",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39354771"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83074",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39354875"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSH to compromise Siebel CRM Cloud Applications.  While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83075",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39354958"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83076",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HR Intelligence",
                    "text": "39355309"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HR Intelligence product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HR Intelligence.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HR Intelligence accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle HR Intelligence. CVSS 3.1 Base Score 6.8 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-33V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-33V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-33V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83077",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39355446"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data as well as  unauthorized read access to a subset of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83078",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39355847"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as  unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83079",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39355889"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications.  While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 7.9 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.9,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83080",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Branch",
                    "text": "39107444"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports).  Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Branch.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Banking Branch. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14324V-14.5.0.0.0-14.9.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14324V-14.5.0.0.0-14.9.0.0.0"
                    ],
                    "url": "https://support.oracle.com"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14324V-14.5.0.0.0-14.9.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83081",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Corporate Lending",
                    "text": "39350586"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Corporate Lending product of Oracle Financial Services Applications (component: Core).  Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Banking Corporate Lending executes to compromise Oracle Banking Corporate Lending.  While the vulnerability is in Oracle Banking Corporate Lending, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Banking Corporate Lending accessible data as well as  unauthorized access to critical data or complete access to all Oracle Banking Corporate Lending accessible data. CVSS 3.1 Base Score 8.0 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-12989V-14.5.0.0.0-14.9.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-12989V-14.5.0.0.0-14.9.0.0.0"
                    ],
                    "url": "https://support.oracle.com"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-12989V-14.5.0.0.0-14.9.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83082",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Marketing",
                    "text": "39383783"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Marketing.  Successful attacks of this vulnerability can result in takeover of Oracle Marketing. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-229V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-229V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-229V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83083",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Marketing",
                    "text": "39383810"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing.  While the vulnerability is in Oracle Marketing, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as  unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-229V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-229V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-229V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83084",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Marketing",
                    "text": "39383813"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing.  While the vulnerability is in Oracle Marketing, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Marketing accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-229V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-229V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-229V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83085",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39357142"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Cloud Applications executes to compromise Siebel CRM Cloud Applications.  While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data as well as  unauthorized update, insert or delete access to some of Siebel CRM Cloud Applications accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83086",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39357552"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Cloud Applications. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83087",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Cloud Applications",
                    "text": "39357602"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager).  Supported versions that are affected are 22.3-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Cloud Applications.  While the vulnerability is in Siebel CRM Cloud Applications, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Cloud Applications accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM Cloud Applications accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14107V-22.3-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14107V-22.3-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14107V-22.3-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83088",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39362864"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Authenticated User privilege with network access via Oracle Net to compromise RDBMS.  While the vulnerability is in RDBMS, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of RDBMS. CVSS 3.1 Base Score 7.7 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU345"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-23.4.0-23.26.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83089",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Alert",
                    "text": "39366709"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Alert product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Alert.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Alert accessible data as well as  unauthorized access to critical data or complete access to all Oracle Alert accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-518V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-518V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-518V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83090",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Spares Management",
                    "text": "39367565"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Spares Management.  Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-754V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-754V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-754V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83091",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Field Service",
                    "text": "39368097"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Field Service accessible data as well as  unauthorized update, insert or delete access to some of Oracle Field Service accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Field Service. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-747V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-747V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-747V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83092",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Field Service",
                    "text": "39368111"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Field Service accessible data as well as  unauthorized access to critical data or complete access to all Oracle Field Service accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Field Service. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-747V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-747V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-747V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83093",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Forms",
                    "text": "39375269"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).  Supported versions that are affected are 12.2.1.19.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms.  While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Forms accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-45V-14.1.2.0.0",
                    "P-45V-12.2.1.19.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83094",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Forms",
                    "text": "39375271"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).  Supported versions that are affected are 12.2.1.19.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms.  Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-45V-14.1.2.0.0",
                    "P-45V-12.2.1.19.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83095",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Forms",
                    "text": "39375272"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).  Supported versions that are affected are 12.2.1.19.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms.  Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-45V-14.1.2.0.0",
                    "P-45V-12.2.1.19.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83096",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Forms",
                    "text": "39375274"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).  Supported versions that are affected are 12.2.1.19.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Forms.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Forms accessible data as well as  unauthorized access to critical data or complete access to all Oracle Forms accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Forms. CVSS 3.1 Base Score 7.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-45V-14.1.2.0.0",
                    "P-45V-12.2.1.19.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.9,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83097",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Forms",
                    "text": "39375275"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).  Supported versions that are affected are 12.2.1.19.0 and  14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Forms.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Forms accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Forms. CVSS 3.1 Base Score 6.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-45V-14.1.2.0.0",
                    "P-45V-12.2.1.19.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83098",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Forms",
                    "text": "39375277"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).  Supported versions that are affected are 12.2.1.19.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms.  Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-45V-14.1.2.0.0",
                    "P-45V-12.2.1.19.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83099",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Forms",
                    "text": "39375279"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).  Supported versions that are affected are 12.2.1.19.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms.  While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-45V-14.1.2.0.0",
                    "P-45V-12.2.1.19.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 10.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83100",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Forms",
                    "text": "39375281"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).  Supported versions that are affected are 12.2.1.19.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms.  Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-45V-14.1.2.0.0",
                    "P-45V-12.2.1.19.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83101",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Forms",
                    "text": "39375283"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).  Supported versions that are affected are 12.2.1.19.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms.  Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-45V-14.1.2.0.0",
                    "P-45V-12.2.1.19.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83102",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Forms",
                    "text": "39375284"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).  Supported versions that are affected are 12.2.1.19.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Forms accessible data as well as  unauthorized access to critical data or complete access to all Oracle Forms accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-45V-14.1.2.0.0",
                    "P-45V-12.2.1.19.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83103",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Forms",
                    "text": "39375285"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).  Supported versions that are affected are 12.2.1.19.0 and  14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Forms.  While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-45V-14.1.2.0.0",
                    "P-45V-12.2.1.19.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83104",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Forms",
                    "text": "39375286"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).  Supported versions that are affected are 12.2.1.19.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Forms.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Forms accessible data as well as  unauthorized access to critical data or complete access to all Oracle Forms accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-45V-14.1.2.0.0",
                    "P-45V-12.2.1.19.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83105",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Forms",
                    "text": "39375287"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).  Supported versions that are affected are 12.2.1.19.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms.  While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-45V-14.1.2.0.0",
                    "P-45V-12.2.1.19.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83106",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Forms",
                    "text": "39375289"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).  Supported versions that are affected are 12.2.1.19.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Forms.  Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-45V-14.1.2.0.0",
                    "P-45V-12.2.1.19.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83107",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Forms",
                    "text": "39375290"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).  Supported versions that are affected are 12.2.1.19.0 and  14.1.2.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Forms.  While the vulnerability is in Oracle Forms, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-45V-14.1.2.0.0",
                    "P-45V-12.2.1.19.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83108",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Forms",
                    "text": "39375292"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).  Supported versions that are affected are 12.2.1.19.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms.  Successful attacks of this vulnerability can result in takeover of Oracle Forms. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-45V-14.1.2.0.0",
                    "P-45V-12.2.1.19.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83109",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Forms",
                    "text": "39375294"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).  Supported versions that are affected are 12.2.1.19.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Forms.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Forms accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-45V-14.1.2.0.0",
                    "P-45V-12.2.1.19.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-45V-14.1.2.0.0",
                        "P-45V-12.2.1.19.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83110",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Marketing",
                    "text": "39383832"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Marketing accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-229V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-229V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-229V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83111",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Partner Management",
                    "text": "39390471"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Partner Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Partner Management.  While the vulnerability is in Oracle Partner Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Partner Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Partner Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1065V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1065V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1065V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83112",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Lease and Finance Management",
                    "text": "39390493"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Lease and Finance Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.7-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Lease and Finance Management.  Successful attacks of this vulnerability can result in takeover of Oracle Lease and Finance Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1056V-12.2.7-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1056V-12.2.7-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1056V-12.2.7-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83113",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Quality",
                    "text": "39390648"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Quality accessible data as well as  unauthorized update, insert or delete access to some of Oracle Quality accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-214V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-214V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-214V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83114",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Quality",
                    "text": "39390666"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Quality product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quality.  Successful attacks of this vulnerability can result in takeover of Oracle Quality. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-214V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-214V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-214V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83115",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Manager",
                    "text": "39383286"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Applications Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-99V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-99V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-99V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83116",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Order Management",
                    "text": "39391103"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).  Supported versions that are affected are 12.2.5-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management.  While the vulnerability is in Oracle Order Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Order Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-497V-12.2.5-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-497V-12.2.5-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-497V-12.2.5-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83117",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Applications DBA",
                    "text": "39383289"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Applications DBA.  Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-166V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-166V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-166V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83118",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Applications DBA",
                    "text": "39383335"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: AD Utilities).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Applications DBA executes to compromise Applications DBA.  Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-166V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-166V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-166V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83119",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle User Management",
                    "text": "39383517"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.6-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management.  Successful attacks of this vulnerability can result in takeover of Oracle User Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1475V-12.2.6-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1475V-12.2.6-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1475V-12.2.6-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83120",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Alert",
                    "text": "39383694"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Alert product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Alert.  Successful attacks of this vulnerability can result in takeover of Oracle Alert. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-518V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-518V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-518V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83121",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Marketing",
                    "text": "39383773"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing.  Successful attacks of this vulnerability can result in takeover of Oracle Marketing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-229V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-229V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-229V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83122",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Report Manager",
                    "text": "39383973"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Report Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Report Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-777V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-777V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-777V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83123",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Report Manager",
                    "text": "39384061"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Report Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Report Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Report Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-777V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-777V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-777V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83124",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Sales Online",
                    "text": "39384126"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Online.  Successful attacks of this vulnerability can result in takeover of Oracle Sales Online. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-758V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-758V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-758V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83125",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Report Manager",
                    "text": "39384132"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Report Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Report Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-777V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-777V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-777V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83126",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Sales Online",
                    "text": "39384133"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Online.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Sales Online, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Sales Online accessible data as well as  unauthorized update, insert or delete access to some of Oracle Sales Online accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-758V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-758V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-758V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83127",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Sales Offline",
                    "text": "39384247"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Offline.  While the vulnerability is in Oracle Sales Offline, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Sales Offline accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1009V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1009V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1009V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83128",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Sales Offline",
                    "text": "39384291"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Sales Offline product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Sales Offline.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Sales Offline accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1009V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1009V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1009V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83129",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Sales",
                    "text": "39384296"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Sales product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales.  While the vulnerability is in Oracle Sales, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Sales accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1558V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1558V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1558V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83130",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Site Hub",
                    "text": "39391591"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Site Hub.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Site Hub accessible data as well as  unauthorized read access to a subset of Oracle Site Hub accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1676V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1676V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1676V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83131",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Web Applications Desktop Integrator",
                    "text": "39384620"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: File download).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Web Applications Desktop Integrator.  While the vulnerability is in Oracle Web Applications Desktop Integrator, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Web Applications Desktop Integrator accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1171V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1171V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1171V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83132",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iStore",
                    "text": "39384992"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle iStore accessible data as well as  unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-384V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-384V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-384V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83133",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iStore",
                    "text": "39384995"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-384V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-384V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-384V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83134",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iStore",
                    "text": "39385012"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore.  While the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-384V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-384V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-384V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83135",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iStore",
                    "text": "39385015"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iStore product of Oracle E-Business Suite (component: Shopping Cart).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iStore.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle iStore, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle iStore accessible data as well as  unauthorized access to critical data or complete access to all Oracle iStore accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-384V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-384V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-384V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83136",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Spares Management",
                    "text": "39390394"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Spares Management.  Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-754V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-754V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-754V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83137",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Spares Management",
                    "text": "39390408"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Spares Management.  Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-754V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-754V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-754V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83138",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Spares Management",
                    "text": "39390593"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Spares Management product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Spares Management.  While the vulnerability is in Oracle Spares Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Spares Management. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-754V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-754V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-754V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83140",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Field Service",
                    "text": "39393067"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Field Service accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-747V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-747V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-747V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83141",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Field Service",
                    "text": "39393127"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service.  While the vulnerability is in Oracle Field Service, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Field Service accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-747V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-747V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-747V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83142",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Proposals",
                    "text": "39394099"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Proposals product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Proposals.  While the vulnerability is in Oracle Proposals, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Proposals accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1333V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1333V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1333V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83143",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel Apps - Life Sciences",
                    "text": "39413355"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM (component: eDetailing).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Life Sciences.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel Apps - Life Sciences accessible data as well as  unauthorized access to critical data or complete access to all Siebel Apps - Life Sciences accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9173V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9173V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9173V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83144",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel Apps - Customer Order Management",
                    "text": "39413412"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel Apps - Customer Order Management product of Oracle Siebel CRM (component: Order Management).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Customer Order Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel Apps - Customer Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel Apps - Customer Order Management accessible data as well as  unauthorized access to critical data or complete access to all Siebel Apps - Customer Order Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8967V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8967V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8967V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83145",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel Apps - Customer Order Management",
                    "text": "39413417"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel Apps - Customer Order Management product of Oracle Siebel CRM (component: Order Management).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Customer Order Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel Apps - Customer Order Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel Apps - Customer Order Management accessible data as well as  unauthorized access to critical data or complete access to all Siebel Apps - Customer Order Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8967V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8967V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8967V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83146",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM End User",
                    "text": "39413431"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI).  Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM End User.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Siebel CRM End User, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9011V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9011V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9011V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83147",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Inventory Brazil",
                    "text": "39435931"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN Inventory Brazil product of Oracle PeopleSoft (component: Inventory).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Inventory Brazil executes to compromise PeopleSoft Enterprise FIN Inventory Brazil.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Inventory Brazil. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4998V-9.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4998V-9.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU354"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4998V-9.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83148",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Testing Suite",
                    "text": "39443841"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Application Testing Suite.   The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Test Manager for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite.  Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4622V-13.3.0.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4622V-13.3.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU346"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4622V-13.3.0.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83149",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Testing Suite",
                    "text": "39443843"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Application Testing Suite.   The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows low privileged attacker having Test Manager for Web Apps privilege with network access via HTTP to compromise Oracle Application Testing Suite.  While the vulnerability is in Oracle Application Testing Suite, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Application Testing Suite accessible data as well as  unauthorized update, insert or delete access to some of Oracle Application Testing Suite accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Application Testing Suite. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4622V-13.3.0.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4622V-13.3.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU346"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4622V-13.3.0.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83150",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Testing Suite",
                    "text": "39443902"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in Oracle Application Testing Suite.   The supported version that is affected is 13.3.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Application Testing Suite executes to compromise Oracle Application Testing Suite.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Application Testing Suite. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4622V-13.3.0.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4622V-13.3.0.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU346"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4622V-13.3.0.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83151",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Service Delivery Platform",
                    "text": "39448733"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Service Delivery Platform.  Successful attacks of this vulnerability can result in takeover of Service Delivery Platform. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2063V-14.1.2.0.0",
                    "P-2063V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2063V-14.1.2.0.0",
                        "P-2063V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83152",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Project Intelligence",
                    "text": "39392816"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Intelligence.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Project Intelligence accessible data as well as  unauthorized access to critical data or complete access to all Oracle Project Intelligence accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1292V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1292V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1292V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83153",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39471005"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83154",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM End User",
                    "text": "39471074"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Siebel CRM End User.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM End User accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9011V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9011V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9011V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83155",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39471118"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Deployment executes to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.3 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83156",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39487170"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle XML Developers Kit component of Oracle Database Server.  Supported versions that are affected are 19.3-19.32, 21.3-21.23 and  23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having XDKC privilege with network access via Oracle Net to compromise Oracle XML Developers Kit.  Successful attacks of this vulnerability can result in takeover of Oracle XML Developers Kit. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Oracle XML Developers Kit)V-19.3-19.32",
                    "P-5(Oracle XML Developers Kit)V-23.4.0-23.26.3",
                    "P-5(Oracle XML Developers Kit)V-21.3-21.23"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Oracle XML Developers Kit)V-19.3-19.32",
                        "P-5(Oracle XML Developers Kit)V-23.4.0-23.26.3",
                        "P-5(Oracle XML Developers Kit)V-21.3-21.23"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU345"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(Oracle XML Developers Kit)V-19.3-19.32",
                        "P-5(Oracle XML Developers Kit)V-23.4.0-23.26.3",
                        "P-5(Oracle XML Developers Kit)V-21.3-21.23"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83157",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Manager",
                    "text": "39488400"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Manager.  While the vulnerability is in Oracle Applications Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Applications Manager. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-99V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-99V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-99V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83158",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Manager",
                    "text": "39488415"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Applications Manager executes to compromise Oracle Applications Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Applications Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Applications Manager accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-99V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-99V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-99V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83159",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Applications DBA",
                    "text": "39488632"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Applications DBA product of Oracle E-Business Suite (component: ADPatch).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Applications DBA executes to compromise Applications DBA.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Applications DBA. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-166V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-166V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-166V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83160",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39489945"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Create Table privilege with network access via Oracle Net to compromise RDBMS.  Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU345"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-23.4.0-23.26.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83161",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Project Intelligence",
                    "text": "39392856"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Intelligence.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Project Intelligence accessible data as well as  unauthorized read access to a subset of Oracle Project Intelligence accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1292V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1292V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1292V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83162",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Object Library",
                    "text": "39493406"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Application Object Library.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as  unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-510V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-510V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-510V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83163",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Object Library",
                    "text": "39493424"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Attachments / File Upload).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library.  Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-510V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-510V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-510V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83164",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Customer Interaction History",
                    "text": "39493537"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Interaction History.  Successful attacks of this vulnerability can result in takeover of Oracle Customer Interaction History. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1374V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1374V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1374V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83165",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Customer Interaction History",
                    "text": "39493542"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: User Interface).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Customer Interaction History.  Successful attacks of this vulnerability can result in takeover of Oracle Customer Interaction History. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1374V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1374V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1374V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83166",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Customer Interaction History",
                    "text": "39493547"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Customer Interaction History product of Oracle E-Business Suite (component: Outcome-Result).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Interaction History.  While the vulnerability is in Oracle Customer Interaction History, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Customer Interaction History accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1374V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1374V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1374V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83167",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Object Library",
                    "text": "39493565"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-510V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-510V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-510V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83168",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Manager",
                    "text": "39493600"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Applications Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Applications Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-99V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-99V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-99V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83169",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle One-to-One Fulfillment",
                    "text": "39493611"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Java Server Issues).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment.  Successful attacks of this vulnerability can result in takeover of Oracle One-to-One Fulfillment. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1379V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1379V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1379V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83170",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle One-to-One Fulfillment",
                    "text": "39493647"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle One-to-One Fulfillment executes to compromise Oracle One-to-One Fulfillment.  Successful attacks of this vulnerability can result in takeover of Oracle One-to-One Fulfillment. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1379V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1379V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1379V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83171",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle One-to-One Fulfillment",
                    "text": "39493723"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment.  While the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle One-to-One Fulfillment. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1379V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1379V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1379V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83172",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Sales Online",
                    "text": "39493760"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Sales Online product of Oracle E-Business Suite (component: OSO Other).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sales Online.  While the vulnerability is in Oracle Sales Online, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Sales Online accessible data as well as  unauthorized update, insert or delete access to some of Oracle Sales Online accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-758V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-758V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-758V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83173",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle One-to-One Fulfillment",
                    "text": "39493768"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle One-to-One Fulfillment. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1379V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1379V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1379V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83174",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle CRM Technical Foundation",
                    "text": "39493776"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Application Framework).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle CRM Technical Foundation.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle CRM Technical Foundation accessible data as well as  unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1199V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1199V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1199V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83175",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Object Library",
                    "text": "39493787"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-510V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-510V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-510V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83176",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Common Applications",
                    "text": "39493950"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Common Applications.  Successful attacks of this vulnerability can result in takeover of Oracle Common Applications. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1198V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1198V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1198V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83177",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle One-to-One Fulfillment",
                    "text": "39493970"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle One-to-One Fulfillment product of Oracle E-Business Suite (component: Documents).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle One-to-One Fulfillment accessible data as well as  unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1379V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1379V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1379V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83178",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Object Library",
                    "text": "39493973"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Application Object Library.  While the vulnerability is in Oracle Application Object Library, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Application Object Library. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-510V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-510V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-510V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83179",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Common Applications Calendar",
                    "text": "39493981"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications Calendar).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications Calendar.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Common Applications Calendar accessible data as well as  unauthorized access to critical data or complete access to all Oracle Common Applications Calendar accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Common Applications Calendar. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1528V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1528V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1528V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83180",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39494389"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83181",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Development",
                    "text": "39494397"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Workspaces).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Development.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Development accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Development. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9001V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9001V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9001V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83182",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Development",
                    "text": "39494405"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Configuration Tools).  Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via SQL to compromise Siebel CRM Development.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9001V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9001V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9001V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83183",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39494562"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83184",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Application Object Library",
                    "text": "39494578"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Application Object Library accessible data as well as  unauthorized access to critical data or complete access to all Oracle Application Object Library accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-510V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-510V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-510V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83185",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Common Applications",
                    "text": "39494608"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Common Applications accessible data as well as  unauthorized access to critical data or complete access to all Oracle Common Applications accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1198V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1198V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1198V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83186",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Common Applications Calendar",
                    "text": "39494617"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications Calendar).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications Calendar.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Common Applications Calendar accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Common Applications Calendar. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1528V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1528V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1528V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83187",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Common Applications Calendar",
                    "text": "39494622"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Applications Calendar).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications Calendar.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Common Applications Calendar accessible data as well as  unauthorized read access to a subset of Oracle Common Applications Calendar accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1528V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1528V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1528V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83188",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Depot Repair",
                    "text": "39392882"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Depot Repair.  Successful attacks of this vulnerability can result in takeover of Oracle Depot Repair. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-516V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-516V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-516V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83189",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle User Management",
                    "text": "39494718"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle User Management product of Oracle E-Business Suite (component: Proxy User Delegation).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle User Management.  Successful attacks of this vulnerability can result in takeover of Oracle User Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1475V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1475V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1475V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83190",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39494799"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83191",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39495019"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83192",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM End User",
                    "text": "39495050"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI).  Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User.  Successful attacks of this vulnerability can result in takeover of Siebel CRM End User. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9011V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9011V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9011V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83193",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel Apps - Life Sciences",
                    "text": "39495140"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel Apps - Life Sciences product of Oracle Siebel CRM (component: Life Sciences).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel Apps - Life Sciences executes to compromise Siebel Apps - Life Sciences.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Siebel Apps - Life Sciences. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9173V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9173V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9173V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83194",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Depot Repair",
                    "text": "39392930"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.10-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Depot Repair.  Successful attacks of this vulnerability can result in takeover of Oracle Depot Repair. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-516V-12.2.10-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-516V-12.2.10-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-516V-12.2.10-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83195",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39496652"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via TCP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83196",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39496657"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Deployment.  While the vulnerability is in Siebel CRM Deployment, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83197",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel Apps - Financial Services",
                    "text": "39496667"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel Apps - Financial Services product of Oracle Siebel CRM (component: Financial Accounts).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - Financial Services.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel Apps - Financial Services accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel Apps - Financial Services. CVSS 3.1 Base Score 9.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9170V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9170V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9170V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83198",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Field Service",
                    "text": "39393100"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Field Service, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Field Service accessible data as well as  unauthorized read access to a subset of Oracle Field Service accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-747V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-747V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-747V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83199",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39496681"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83200",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Process Manufacturing Intelligence",
                    "text": "39393221"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Process Manufacturing Intelligence product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via Oracle Net to compromise Oracle Process Manufacturing Intelligence.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Process Manufacturing Intelligence accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-23V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-23V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-23V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83201",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39496711"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Deployment accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83202",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39496716"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Deployment accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83203",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM End User",
                    "text": "39496719"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data as well as  unauthorized update, insert or delete access to some of Siebel CRM End User accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM End User. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9011V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9011V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9011V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83204",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Sourcing",
                    "text": "39393510"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Sourcing product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sourcing.  Successful attacks of this vulnerability can result in takeover of Oracle Sourcing. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1273V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1273V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1273V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83205",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Framework",
                    "text": "39647377"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1472V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1472V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1472V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83206",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Corporate Lending Process Management",
                    "text": "39723140"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Corporate Lending Process Management product of Oracle Financial Services Applications (component: Base).  Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Corporate Lending Process Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Banking Corporate Lending Process Management. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13701V-14.5.0.0.0-14.9.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13701V-14.5.0.0.0-14.9.0.0.0"
                    ],
                    "url": "https://support.oracle.com"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13701V-14.5.0.0.0-14.9.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83207",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Development",
                    "text": "39496736"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Integration - Scripting).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Development.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Development as well as  unauthorized update, insert or delete access to some of Siebel CRM Development accessible data and  unauthorized read access to a subset of Siebel CRM Development accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9001V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9001V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9001V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83208",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39496742"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83209",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Development",
                    "text": "39496768"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Development product of Oracle Siebel CRM (component: Workflow).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Development.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Development. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9001V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9001V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9001V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83210",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39496773"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83211",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39496781"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83212",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel Apps - Self Service",
                    "text": "39496790"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel Apps - Self Service product of Oracle Siebel CRM (component: Helpdesk/Training).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel Apps - Self Service.  Successful attacks of this vulnerability can result in takeover of Siebel Apps - Self Service. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8982V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8982V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8982V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83213",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM End User",
                    "text": "39496801"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Reports).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM End User.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9011V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9011V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9011V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83214",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39496826"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83215",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39496835"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data as well as  unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83216",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39496837"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83217",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM End User",
                    "text": "39496847"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM End User product of Oracle Siebel CRM (component: Open UI).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM End User.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM End User accessible data as well as  unauthorized update, insert or delete access to some of Siebel CRM End User accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9011V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9011V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9011V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83218",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39496885"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Deployment accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83219",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39496893"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Siebel CRM Deployment executes to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Deployment accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83220",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39496929"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Event Publish and Subscribe).  Supported versions that are affected are 23.6-26.7. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Siebel CRM Integration executes to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Siebel CRM Integration accessible data as well as  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-23.6-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-23.6-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9008V-23.6-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83221",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39496943"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data as well as  unauthorized update, insert or delete access to some of Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9008V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83222",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39497071"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83223",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39497076"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Remote).  Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83224",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39497080"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83225",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39497081"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83226",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39497083"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83227",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39497086"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: EAI).  Supported versions that are affected are 17.0-26.7. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in takeover of Siebel CRM Integration. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9008V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83228",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39497091"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Server Infrastructure).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Siebel CRM Deployment. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83229",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39499552"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Management Console).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Siebel CRM Deployment.  While the vulnerability is in Siebel CRM Deployment, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Siebel CRM Deployment. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83230",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Deployment",
                    "text": "39499592"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Siebel Management Console).  Supported versions that are affected are 17.0-26.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel CRM Deployment.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Deployment accessible data as well as  unauthorized update, insert or delete access to some of Siebel CRM Deployment accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9019V-17.0-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9019V-17.0-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9019V-17.0-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83231",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Helidon",
                    "text": "39727378"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-dbclient-mongodb).  Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Helidon accessible data as well as  unauthorized update, insert or delete access to some of Helidon accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13972V-4.0.0-4.5.4",
                    "P-13972V-3.0.0-3.2.20"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13972V-4.0.0-4.5.4",
                        "P-13972V-3.0.0-3.2.20"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU357"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13972V-4.0.0-4.5.4",
                        "P-13972V-3.0.0-3.2.20"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83232",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Data Integrator",
                    "text": "39508131"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Console / Repository Explorer).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Data Integrator.  Successful attacks of this vulnerability can result in takeover of Oracle Data Integrator. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2196V-14.1.2.0.0",
                    "P-2196V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2196V-12.2.1.4.0",
                        "P-2196V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2196V-12.2.1.4.0",
                        "P-2196V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83233",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39527996"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83234",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39528000"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as  unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83235",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39528132"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83236",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39528205"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as  unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83237",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39528306"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83238",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39528344"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83239",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39528445"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Endeca Application Controller)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Endeca Application Controller)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Endeca Application Controller)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83240",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39528491"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83241",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39528553"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83242",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39528915"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as  unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83243",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39528924"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Experience Manager).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Experience Manager)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83244",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39529099"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as  unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83245",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39529101"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83246",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39529108"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83247",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39529111"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83248",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39529113"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager and  unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83249",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39529116"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  While the vulnerability is in Oracle Commerce Guided Search / Oracle Commerce Experience Manager, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83250",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39529121"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 6.5 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83251",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39529137"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager and  unauthorized read access to a subset of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83252",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39529138"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data as well as  unauthorized update, insert or delete access to some of Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83253",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39529140"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Endeca Application Controller).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Commerce Guided Search / Oracle Commerce Experience Manager executes to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Endeca Application Controller)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Endeca Application Controller)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Endeca Application Controller)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83254",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39529141"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83255",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39529143"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83256",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39529148"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83257",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39529152"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83258",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39529154"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83259",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Commerce Guided Search / Oracle Commerce Experience Manager",
                    "text": "39529155"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (component: Forge).   The supported version that is affected is 11.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU352"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9633(Oracle Commerce Guided Search / Oracle Commerce Experience Manager_Forge)V-11.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83260",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39529635"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Event Java PX).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows high privileged attacker with network access via T3, IIOP to compromise Oracle Agile PLM.  While the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4461V-9.3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4461V-9.3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83261",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Lifecycle Analytics",
                    "text": "39529857"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Core).   The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics.  Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9387V-3.6.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9387V-3.6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9387V-3.6.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83262",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Lifecycle Analytics",
                    "text": "39529892"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).   The supported version that is affected is 3.6.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics.  Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9387V-3.6.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9387V-3.6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9387V-3.6.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83263",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Lifecycle Analytics",
                    "text": "39529897"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).   The supported version that is affected is 3.6.1. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Lifecycle Analytics.  Successful attacks of this vulnerability can result in takeover of Oracle Product Lifecycle Analytics. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9387V-3.6.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9387V-3.6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9387V-3.6.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83264",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Lifecycle Analytics",
                    "text": "39529958"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).   The supported version that is affected is 3.6.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Product Lifecycle Analytics executes to compromise Oracle Product Lifecycle Analytics.  While the vulnerability is in Oracle Product Lifecycle Analytics, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Lifecycle Analytics accessible data as well as  unauthorized access to critical data or complete access to all Oracle Product Lifecycle Analytics accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9387V-3.6.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9387V-3.6.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9387V-3.6.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83265",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Web Services Manager",
                    "text": "39532666"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Agent).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Services Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Web Services Manager accessible data as well as  unauthorized update, insert or delete access to some of Oracle Web Services Manager accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1775V-14.1.2.0.0",
                    "P-1775V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1775V-12.2.1.4.0",
                        "P-1775V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1775V-12.2.1.4.0",
                        "P-1775V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83266",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle JDeveloper",
                    "text": "39532679"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle JDeveloper. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-807V-14.1.2.0.0",
                    "P-807V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83267",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39532693"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Publisher Security).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as  unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83268",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39532707"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83269",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39532955"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83270",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39540667"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security).  Supported versions that are affected are 8.2.0.0.0 and  26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83271",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39570655"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 19.3-19.32, 21.3-21.23 and  23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Execute on DBMS_REDEFINITION privilege with network access via Oracle Net to compromise RDBMS.  Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(RDBMS)V-19.3-19.32",
                    "P-5(RDBMS)V-21.3-21.23",
                    "P-5(RDBMS)V-23.4.0-23.26.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-19.3-19.32",
                        "P-5(RDBMS)V-21.3-21.23",
                        "P-5(RDBMS)V-23.4.0-23.26.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU345"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-19.3-19.32",
                        "P-5(RDBMS)V-21.3-21.23",
                        "P-5(RDBMS)V-23.4.0-23.26.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83272",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39570736"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Text component of Oracle Database Server.  Supported versions that are affected are 19.3-19.32, 21.3-21.23 and  23.4.0-23.26.3. Difficult to exploit vulnerability allows low privileged attacker having Create Index privilege with network access via Oracle Net to compromise Oracle Text.  While the vulnerability is in Oracle Text, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Text. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Oracle Text)V-23.4.0-23.26.3",
                    "P-5(Oracle Text)V-21.3-21.23",
                    "P-5(Oracle Text)V-19.3-19.32"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Oracle Text)V-19.3-19.32",
                        "P-5(Oracle Text)V-23.4.0-23.26.3",
                        "P-5(Oracle Text)V-21.3-21.23"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU345"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(Oracle Text)V-19.3-19.32",
                        "P-5(Oracle Text)V-23.4.0-23.26.3",
                        "P-5(Oracle Text)V-21.3-21.23"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83273",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39574696"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security).   The supported version that is affected is 26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-26.01.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83274",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM MCAD Connector",
                    "text": "39579743"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client).   The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4440V-3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4440V-3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4440V-3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83276",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Helidon",
                    "text": "39727395"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webclient-http2).  Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13972V-4.0.0-4.5.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13972V-4.0.0-4.5.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU357"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13972V-4.0.0-4.5.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83277",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM MCAD Connector",
                    "text": "39579765"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client).   The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector.  While the vulnerability is in Oracle Agile PLM MCAD Connector, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM MCAD Connector accessible data as well as  unauthorized read access to a subset of Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4440V-3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4440V-3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4440V-3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83278",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Helidon",
                    "text": "39727409"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-integrations-neo4j).  Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Helidon executes to compromise Helidon.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as  unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13972V-4.0.0-4.5.4",
                    "P-13972V-3.0.0-3.2.20"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13972V-4.0.0-4.5.4",
                        "P-13972V-3.0.0-3.2.20"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU357"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13972V-4.0.0-4.5.4",
                        "P-13972V-3.0.0-3.2.20"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83279",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM MCAD Connector",
                    "text": "39579791"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client).   The supported version that is affected is 3.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile PLM MCAD Connector executes to compromise Oracle Agile PLM MCAD Connector.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM MCAD Connector accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4440V-3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4440V-3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4440V-3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83280",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Helidon",
                    "text": "39727420"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-http2).  Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP/2 to compromise Helidon.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13972V-4.0.0-4.5.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13972V-4.0.0-4.5.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU357"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13972V-4.0.0-4.5.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83281",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Helidon",
                    "text": "39727433"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver).  Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Helidon.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13972V-4.0.0-4.5.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13972V-4.0.0-4.5.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU357"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13972V-4.0.0-4.5.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83282",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638301"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83283",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638317"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83284",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39638321"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle BI Publisher as well as  unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and  unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83285",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638339"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83286",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638341"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0",
                    "P-2025V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83287",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638342"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Business Intelligence Enterprise Edition.  While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0",
                    "P-2025V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83288",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638343"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0",
                    "P-2025V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83289",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638347"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0",
                    "P-2025V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83290",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638350"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security).  Supported versions that are affected are 8.2.0.0.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83291",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638359"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security).  Supported versions that are affected are 8.2.0.0.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83292",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638365"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security).  Supported versions that are affected are 8.2.0.0.0 and  26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83293",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638370"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: FNDN).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83294",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638371"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0",
                    "P-2025V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83295",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638373"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Presentation Services).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0",
                    "P-2025V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83296",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638379"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Search).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0",
                    "P-2025V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83297",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39638381"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via LDAP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83298",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39638388"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83299",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638402"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General).   The supported version that is affected is 12.2.1.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83300",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle XML Gateway",
                    "text": "39313212"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle XML Gateway.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle XML Gateway. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-757V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-757V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-757V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83301",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638409"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Service Administration UI).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83302",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39638419"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Publisher Security).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.5 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83303",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39638420"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher.  While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as  unauthorized read access to a subset of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83304",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638425"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web General).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0",
                    "P-2025V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.9,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83305",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39638431"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as  unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83306",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle JDeveloper",
                    "text": "39638432"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Resource Catalog Services).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-807V-14.1.2.0.0",
                    "P-807V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83307",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39638438"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83308",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39638444"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83309",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39638446"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Server).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as  unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83310",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39638452"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data as well as  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83311",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39638454"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher.  While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as  unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83312",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39638462"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: E-Business Suite - XDO).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83313",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39638463"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83314",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39638472"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle BI Publisher accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle BI Publisher. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83315",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39638473"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83316",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638513"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security).   The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-26.01.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83317",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638745"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Installation).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0",
                    "P-2025V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-12.2.1.4.0",
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83318",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39638851"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks of this vulnerability can result in takeover of Oracle BI Publisher. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83319",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39638859"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Web Service API).   The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via SOAP to compromise Oracle BI Publisher.  While the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83320",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle BI Publisher",
                    "text": "39638870"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: Administration).  Supported versions that are affected are 8.2.0.0.0, 12.2.1.4.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle BI Publisher.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle BI Publisher, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle BI Publisher accessible data as well as  unauthorized update, insert or delete access to some of Oracle BI Publisher accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1479V-26.01.0.0.0",
                    "P-1479V-8.2.0.0.0",
                    "P-1479V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1479V-26.01.0.0.0",
                        "P-1479V-8.2.0.0.0",
                        "P-1479V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83321",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638949"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Actions).  Supported versions that are affected are 8.2.0.0.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized update, insert or delete access to some of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83322",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638959"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security).  Supported versions that are affected are 8.2.0.0.0 and  26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83323",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39638986"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security).   The supported version that is affected is 26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-26.01.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83324",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39639058"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform Security).  Supported versions that are affected are 8.2.0.0.0 and  26.01.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  While the vulnerability is in Oracle Business Intelligence Enterprise Edition, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Business Intelligence Enterprise Edition accessible data as well as  unauthorized read access to a subset of Oracle Business Intelligence Enterprise Edition accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83325",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39639078"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Platform Security).  Supported versions that are affected are 8.2.0.0.0 and  26.01.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83326",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Siebel CRM Integration",
                    "text": "39646630"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration).  Supported versions that are affected are 25.12-26.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel CRM Integration.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Siebel CRM Integration accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-9008V-25.12-26.7"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-9008V-25.12-26.7"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU353"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-9008V-25.12-26.7"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83327",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Framework",
                    "text": "39647763"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Applications Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1472V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1472V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1472V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83328",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Framework",
                    "text": "39647802"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1472V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1472V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1472V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83329",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Framework",
                    "text": "39647954"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization).  Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1472V-12.2.9-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1472V-12.2.9-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1472V-12.2.9-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83330",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Helidon",
                    "text": "39727435"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket).  Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13972V-4.0.0-4.5.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13972V-4.0.0-4.5.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU357"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13972V-4.0.0-4.5.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83331",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Framework",
                    "text": "39648077"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization).  Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1472V-12.2.9-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1472V-12.2.9-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1472V-12.2.9-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83332",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Framework",
                    "text": "39648629"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization).  Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Applications Framework accessible data as well as  unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1472V-12.2.9-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1472V-12.2.9-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1472V-12.2.9-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83333",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39661137"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Net Services component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Oracle Net Services)V-23.4.0-23.26.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Oracle Net Services)V-23.4.0-23.26.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU345"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(Oracle Net Services)V-23.4.0-23.26.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83334",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Web Services Manager",
                    "text": "39680232"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middleware (component: Web Services Security).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Web Services Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Web Services Manager accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Web Services Manager. CVSS 3.1 Base Score 7.4 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1775V-14.1.2.0.0",
                    "P-1775V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1775V-12.2.1.4.0",
                        "P-1775V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1775V-12.2.1.4.0",
                        "P-1775V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83335",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39699740"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server).  Supported versions that are affected are 8.2.0.0.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83336",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Business Intelligence Enterprise Edition",
                    "text": "39699756"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Server).  Supported versions that are affected are 8.2.0.0.0 and  26.01.0.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Business Intelligence Enterprise Edition executes to compromise Oracle Business Intelligence Enterprise Edition.  Successful attacks of this vulnerability can result in takeover of Oracle Business Intelligence Enterprise Edition. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2025V-8.2.0.0.0",
                    "P-2025V-26.01.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU341"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2025V-8.2.0.0.0",
                        "P-2025V-26.01.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83337",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Middleware Common Libraries and Tools",
                    "text": "39704376"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Middleware Common Libraries and Tools product of Oracle Fusion Middleware (component: Remote Diagnostic Agent).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Middleware Common Libraries and Tools executes to compromise Oracle Middleware Common Libraries and Tools.  Successful attacks of this vulnerability can result in takeover of Oracle Middleware Common Libraries and Tools. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4647V-12.2.1.4.0",
                    "P-4647V-14.1.1.0.0",
                    "P-4647V-14.1.2.0.0",
                    "P-4647V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4647V-14.1.1.0.0",
                        "P-4647V-14.1.2.0.0",
                        "P-4647V-12.2.1.4.0",
                        "P-4647V-15.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4647V-14.1.1.0.0",
                        "P-4647V-14.1.2.0.0",
                        "P-4647V-12.2.1.4.0",
                        "P-4647V-15.1.1.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83338",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Manager",
                    "text": "39704971"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Oracle Diagnostics Interfaces).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Applications Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-99V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-99V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-99V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83339",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Enterprise Capture",
                    "text": "39725936"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Enterprise Capture product of Oracle Fusion Middleware (component: Client Bundle).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Enterprise Capture.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Enterprise Capture. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-10212V-14.1.2.0.0",
                    "P-10212V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-10212V-14.1.2.0.0",
                        "P-10212V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83340",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39726268"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: Security).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1980V-12.2.1.4.0",
                    "P-1980V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83341",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Applications Manager",
                    "text": "39737001"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Command Line - RapidClone).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Applications Manager accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-99V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-99V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-99V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83342",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
                    "text": "39739507"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide).  Supported versions that are affected are 2.4.0.1.0-2.4.0.1.33, 2.5.0.1.0-2.5.0.1.19, 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A and  25.12.0.0.0-25.12.0.0.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Utilities Network Management System executes to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Network Management System. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2241V-2.5.0.1.0-2.5.0.1.19",
                    "P-2241V-25.12.0.0.0-25.12.0.0.3",
                    "P-2241V-2.4.0.1.0-2.4.0.1.33",
                    "P-2241V-2.6.0.1.0-2.6.0.12B",
                    "P-2241V-2.5.0.2.0-2.5.0.2.13",
                    "P-2241V-2.6.0.2.0-2.6.0.2.10A"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2241V-2.5.0.1.0-2.5.0.1.19",
                        "P-2241V-25.12.0.0.0-25.12.0.0.3",
                        "P-2241V-2.4.0.1.0-2.4.0.1.33",
                        "P-2241V-2.6.0.1.0-2.6.0.12B",
                        "P-2241V-2.5.0.2.0-2.5.0.2.13",
                        "P-2241V-2.6.0.2.0-2.6.0.2.10A"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU356"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2241V-2.5.0.1.0-2.5.0.1.19",
                        "P-2241V-25.12.0.0.0-25.12.0.0.3",
                        "P-2241V-2.4.0.1.0-2.4.0.1.33",
                        "P-2241V-2.6.0.1.0-2.6.0.12B",
                        "P-2241V-2.5.0.2.0-2.5.0.2.13",
                        "P-2241V-2.6.0.2.0-2.6.0.2.10A"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83343",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Utilities Network Management System",
                    "text": "39739539"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: System Wide).  Supported versions that are affected are 2.5.0.2.0-2.5.0.2.13, 2.6.0.1.0-2.6.0.12B, 2.6.0.2.0-2.6.0.2.10A and  25.12.0.0.0-25.12.0.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Network Management System.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Utilities Network Management System accessible data as well as  unauthorized update, insert or delete access to some of Oracle Utilities Network Management System accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2241V-25.12.0.0.0-25.12.0.0.3",
                    "P-2241V-2.5.0.2.0-2.5.0.2.13",
                    "P-2241V-2.6.0.2.0-2.6.0.2.10A",
                    "P-2241V-2.6.0.1.0-2.6.0.12B"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2241V-25.12.0.0.0-25.12.0.0.3",
                        "P-2241V-2.6.0.1.0-2.6.0.12B",
                        "P-2241V-2.5.0.2.0-2.5.0.2.13",
                        "P-2241V-2.6.0.2.0-2.6.0.2.10A"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU356"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2241V-25.12.0.0.0-25.12.0.0.3",
                        "P-2241V-2.6.0.1.0-2.6.0.12B",
                        "P-2241V-2.5.0.2.0-2.5.0.2.13",
                        "P-2241V-2.6.0.2.0-2.6.0.2.10A"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83344",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager Connector",
                    "text": "39744885"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Database Application Table).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Identity Manager Connector.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1999V-12.2.1.4.0",
                    "P-1999V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1999V-14.1.2.1.0",
                        "P-1999V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83345",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle XML Gateway",
                    "text": "39313236"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle XML Gateway.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle XML Gateway. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-757V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-757V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-757V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83346",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Fusion Middleware Control",
                    "text": "39760302"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Fusion Middleware Control product of Oracle Fusion Middleware (component: Framework).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Fusion Middleware Control.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Fusion Middleware Control, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Fusion Middleware Control accessible data as well as  unauthorized read access to a subset of Oracle Fusion Middleware Control accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14309V-12.2.1.4.0",
                    "P-14309V-14.1.2.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14309V-12.2.1.4.0",
                        "P-14309V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14309V-12.2.1.4.0",
                        "P-14309V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83347",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39761035"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Net Services component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCPS to compromise Oracle Net Services.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Oracle Net Services)V-23.4.0-23.26.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Oracle Net Services)V-23.4.0-23.26.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU345"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(Oracle Net Services)V-23.4.0-23.26.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83348",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39761039"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 19.3-19.32, 21.3-21.23 and  23.4.0-23.26.3. Easily exploitable vulnerability allows low privileged attacker having Create DB Link privilege with network access via Oracle Net to compromise RDBMS.  Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(RDBMS)V-19.3-19.32",
                    "P-5(RDBMS)V-21.3-21.23",
                    "P-5(RDBMS)V-23.4.0-23.26.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-19.3-19.32",
                        "P-5(RDBMS)V-21.3-21.23",
                        "P-5(RDBMS)V-23.4.0-23.26.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU345"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-19.3-19.32",
                        "P-5(RDBMS)V-21.3-21.23",
                        "P-5(RDBMS)V-23.4.0-23.26.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83349",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39761126"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Net Services component of Oracle Database Server.  Supported versions that are affected are 19.3-19.32, 21.3-21.23 and  23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Oracle Net Services)V-23.4.0-23.26.3",
                    "P-5(Oracle Net Services)V-19.3-19.32",
                    "P-5(Oracle Net Services)V-21.3-21.23"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Oracle Net Services)V-23.4.0-23.26.3",
                        "P-5(Oracle Net Services)V-19.3-19.32",
                        "P-5(Oracle Net Services)V-21.3-21.23"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU345"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(Oracle Net Services)V-23.4.0-23.26.3",
                        "P-5(Oracle Net Services)V-19.3-19.32",
                        "P-5(Oracle Net Services)V-21.3-21.23"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83350",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39761130"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Net Services component of Oracle Database Server.  Supported versions that are affected are 21.3-21.23 and  23.4.0-23.26.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Net Services.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Net Services. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(Oracle Net Services)V-23.4.0-23.26.3",
                    "P-5(Oracle Net Services)V-21.3-21.23"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(Oracle Net Services)V-23.4.0-23.26.3",
                        "P-5(Oracle Net Services)V-21.3-21.23"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU345"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(Oracle Net Services)V-23.4.0-23.26.3",
                        "P-5(Oracle Net Services)V-21.3-21.23"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83351",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Database Server",
                    "text": "39761158"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the RDBMS component of Oracle Database Server.  Supported versions that are affected are 23.4.0-23.26.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS.  Successful attacks of this vulnerability can result in takeover of RDBMS. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5(RDBMS)V-23.4.0-23.26.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5(RDBMS)V-23.4.0-23.26.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU345"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5(RDBMS)V-23.4.0-23.26.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83352",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle XML Gateway",
                    "text": "39314460"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle XML Gateway product of Oracle E-Business Suite (component: Install).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle XML Gateway.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle XML Gateway. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-757V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-757V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-757V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83353",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle WebCenter Content",
                    "text": "39766041"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle WebCenter Content executes to compromise Oracle WebCenter Content.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Content. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2271V-14.1.2.0.0",
                    "P-2271V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2271V-14.1.2.0.0",
                        "P-2271V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Samet Akilli"
                    ]
                }
            ],
            "cve": "CVE-2026-83354",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39766200"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).   The supported version that is affected is 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence.  While the vulnerability is in Oracle Coherence, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 6.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83355",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Enterprise Manager for Fusion Middleware",
                    "text": "39769446"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: Metrics).  Supported versions that are affected are 13.5 and  24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Enterprise Manager for Fusion Middleware.  Successful attacks of this vulnerability can result in takeover of Oracle Enterprise Manager for Fusion Middleware. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1369(Oracle Enterprise Manager for Fusion Middleware_Metrics)V-24.1",
                    "P-1369(Oracle Enterprise Manager for Fusion Middleware_Metrics)V-13.5"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1369(Oracle Enterprise Manager for Fusion Middleware_Metrics)V-24.1",
                        "P-1369(Oracle Enterprise Manager for Fusion Middleware_Metrics)V-13.5"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU350"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1369(Oracle Enterprise Manager for Fusion Middleware_Metrics)V-24.1",
                        "P-1369(Oracle Enterprise Manager for Fusion Middleware_Metrics)V-13.5"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83356",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Enterprise Command Center Framework",
                    "text": "39315618"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Enterprise Command Center Framework product of Oracle E-Business Suite (component: Security).   The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Enterprise Command Center Framework.  While the vulnerability is in Enterprise Command Center Framework, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Enterprise Command Center Framework accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13788V-V16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13788V-V16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13788V-V16"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83357",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GraalVM for JDK, Oracle GraalVM",
                    "text": "39770618"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler).   The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1;  Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM for JDK, Oracle GraalVM.  Successful attacks of this vulnerability can result in takeover of Oracle GraalVM for JDK, Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13497V-23.0.13.1",
                    "P-13497V-23.1.12.1",
                    "P-13497V-25.0.4.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13497V-23.0.13.1",
                        "P-13497V-23.1.12.1",
                        "P-13497V-25.0.4.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU349"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13497V-23.0.13.1",
                        "P-13497V-23.1.12.1",
                        "P-13497V-25.0.4.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83368",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GraalVM for JDK",
                    "text": "39776460"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM product of Oracle Java SE (component: Compiler).   The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1; Oracle GraalVM Enterprise Edition: 21.3.19.1; Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM accessible data as well as  unauthorized update, insert or delete access to some of Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition, Oracle GraalVM. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13497V-21.3.19.1",
                    "P-13497V-23.0.13.1",
                    "P-13497V-23.1.12.1",
                    "P-13497V-25.0.4.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13497V-23.0.13.1",
                        "P-13497V-21.3.19.1",
                        "P-13497V-23.1.12.1",
                        "P-13497V-25.0.4.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU349"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13497V-23.0.13.1",
                        "P-13497V-21.3.19.1",
                        "P-13497V-23.1.12.1",
                        "P-13497V-25.0.4.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83369",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Access Manager",
                    "text": "39777795"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Access SDK).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Access Manager. CVSS 3.1 Base Score 3.1 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5565V-14.1.2.1.0",
                    "P-5565V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.1,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5565V-14.1.2.1.0",
                        "P-5565V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83408",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GraalVM for JDK, Oracle GraalVM",
                    "text": "39805934"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler).   The supported version that is affected is Oracle GraalVM for JDK 17: 23.0.13.1; Oracle GraalVM for JDK 21: 23.1.12.1;  Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM for JDK, Oracle GraalVM.  Successful attacks of this vulnerability can result in takeover of Oracle GraalVM for JDK, Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13497V-23.0.13.1",
                    "P-13497V-23.1.12.1",
                    "P-13497V-25.0.4.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13497V-23.0.13.1",
                        "P-13497V-23.1.12.1",
                        "P-13497V-25.0.4.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU349"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13497V-23.0.13.1",
                        "P-13497V-23.1.12.1",
                        "P-13497V-25.0.4.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83410",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39848741"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83411",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39848850"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83412",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39848865"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Coherence accessible data as well as  unauthorized access to critical data or complete access to all Oracle Coherence accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83413",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39848868"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Coherence accessible data. CVSS 3.1 Base Score 1.9 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 1.9,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83414",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39848880"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).   The supported version that is affected is 15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Coherence executes to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Coherence accessible data. CVSS 3.1 Base Score 2.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-15.1.1.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 2.5,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-15.1.1.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83415",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39848885"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in takeover of Oracle Coherence. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83416",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Coherence",
                    "text": "39848891"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0 and  15.1.1.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Coherence.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Coherence. CVSS 3.1 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2545V-14.1.1.0.0",
                    "P-2545V-14.1.2.0.0",
                    "P-2545V-12.2.1.4.0",
                    "P-2545V-15.1.1.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2545V-12.2.1.4.0",
                        "P-2545V-15.1.1.0.0",
                        "P-2545V-14.1.1.0.0",
                        "P-2545V-14.1.2.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83417",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39867550"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP).  Supported versions that are affected are 26.1.200 and  25.2.201. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Communications Cloud Native Core Security Edge Protection Proxy executes to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.201",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-26.1.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.201",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-26.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU348"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.201",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-26.1.200"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83418",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39867719"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP).  Supported versions that are affected are 26.1.200 and  25.2.201. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  While the vulnerability is in Oracle Communications Cloud Native Core Security Edge Protection Proxy, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized access to critical data or complete access to all Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.201",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-26.1.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.201",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-26.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU348"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.201",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-26.1.200"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83419",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Cloud Native Core Security Edge Protection Proxy",
                    "text": "39867757"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Cloud Native Core Security Edge Protection Proxy product of Oracle Communications (component: SEPP).  Supported versions that are affected are 26.1.200 and  25.2.201. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Cloud Native Core Security Edge Protection Proxy.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data as well as  unauthorized read access to a subset of Oracle Communications Cloud Native Core Security Edge Protection Proxy accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.201",
                    "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-26.1.200"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.201",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-26.1.200"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU348"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-25.2.201",
                        "P-14123(Oracle Communications Cloud Native Core Security Edge Protection Proxy_SEPP)V-26.1.200"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83420",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise FIN Engineering Brazil",
                    "text": "39931463"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise FIN Engineering Brazil product of Oracle PeopleSoft (component: Engineering).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Engineering Brazil executes to compromise PeopleSoft Enterprise FIN Engineering Brazil.  Successful attacks of this vulnerability can result in takeover of PeopleSoft Enterprise FIN Engineering Brazil. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4914V-9.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4914V-9.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU354"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4914V-9.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83422",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Identity Manager",
                    "text": "39271531"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Identity Manager.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Identity Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Identity Manager accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1980V-12.2.1.4.0",
                    "P-1980V-14.1.2.1.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1980V-14.1.2.1.0",
                        "P-1980V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83423",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle JDeveloper",
                    "text": "39326382"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in takeover of Oracle JDeveloper. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-807V-14.1.2.0.0",
                    "P-807V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83424",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle JDeveloper",
                    "text": "39326391"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Oracle JDeveloper).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle JDeveloper.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle JDeveloper accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-807V-14.1.2.0.0",
                    "P-807V-12.2.1.4.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU340"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-807V-14.1.2.0.0",
                        "P-807V-12.2.1.4.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83425",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Complex Maintenance, Repair and Overhaul",
                    "text": "39351504"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.12-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair and Overhaul.  While the vulnerability is in Oracle Complex Maintenance, Repair and Overhaul, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Complex Maintenance, Repair and Overhaul accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 8.5 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1184V-12.2.12-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1184V-12.2.12-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1184V-12.2.12-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83428",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Demand Signal Repository",
                    "text": "39359906"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Demand Signal Repository accessible data as well as  unauthorized access to critical data or complete access to all Oracle Demand Signal Repository accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4546V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4546V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4546V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83429",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Demand Signal Repository",
                    "text": "39359928"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Demand Signal Repository accessible data as well as  unauthorized access to critical data or complete access to all Oracle Demand Signal Repository accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4546V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4546V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4546V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83430",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Workbench",
                    "text": "39366223"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Workbench accessible data as well as  unauthorized access to critical data or complete access to all Oracle Product Workbench accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1597V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1597V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1597V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83431",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Workbench",
                    "text": "39366312"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: WebUI).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Product Workbench, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Product Workbench accessible data as well as  unauthorized read access to a subset of Oracle Product Workbench accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1597V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1597V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1597V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83432",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Depot Repair",
                    "text": "39366320"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Estimate and Actual Charges).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Depot Repair.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Depot Repair accessible data as well as  unauthorized access to critical data or complete access to all Oracle Depot Repair accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-516V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-516V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-516V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83433",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Depot Repair",
                    "text": "39366367"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Depot Repair Diagnostics).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Depot Repair.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Depot Repair accessible data as well as  unauthorized access to critical data or complete access to all Oracle Depot Repair accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-516V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-516V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-516V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83434",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Workbench",
                    "text": "39366446"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Workbench accessible data as well as  unauthorized access to critical data or complete access to all Oracle Product Workbench accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1597V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1597V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1597V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83435",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Bills of Material",
                    "text": "39368974"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.13-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material.  While the vulnerability is in Oracle Bills of Material, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Bills of Material accessible data as well as  unauthorized access to critical data or complete access to all Oracle Bills of Material accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-571V-12.2.13-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-571V-12.2.13-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-571V-12.2.13-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83436",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Depot Repair",
                    "text": "39379644"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Depot Repair product of Oracle E-Business Suite (component: Recall Management).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Depot Repair.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Depot Repair accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Depot Repair. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-516V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-516V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-516V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83437",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Engineering",
                    "text": "39382554"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Change Management).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Engineering.  While the vulnerability is in Oracle Engineering, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Engineering accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-532V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-532V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-532V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83438",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Engineering",
                    "text": "39382576"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Engineering product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Engineering.  While the vulnerability is in Oracle Engineering, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Engineering accessible data as well as  unauthorized access to critical data or complete access to all Oracle Engineering accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-532V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-532V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-532V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83439",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Helidon",
                    "text": "39727441"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-security-providers-idcs-mapper).  Supported versions that are affected are 3.0.0-3.2.20 and 4.0.0-4.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Helidon accessible data as well as  unauthorized access to critical data or complete access to all Helidon accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13972V-4.0.0-4.5.4",
                    "P-13972V-3.0.0-3.2.20"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13972V-4.0.0-4.5.4",
                        "P-13972V-3.0.0-3.2.20"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU357"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13972V-4.0.0-4.5.4",
                        "P-13972V-3.0.0-3.2.20"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83440",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Hub",
                    "text": "39382608"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Product Hub.  Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1313V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1313V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1313V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83441",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Hub",
                    "text": "39382679"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Hub accessible data as well as  unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1313V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1313V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1313V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83442",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Hub",
                    "text": "39382713"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Product Hub.  Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1313V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1313V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1313V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83443",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Assets",
                    "text": "39382729"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Assets product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Assets.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Assets accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-503V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-503V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-503V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83444",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Hub",
                    "text": "39382763"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub.  Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1313V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1313V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1313V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83445",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Complex Maintenance, Repair and Overhaul",
                    "text": "39383523"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Complex Maintenance, Repair and Overhaul.  Successful attacks of this vulnerability can result in takeover of Oracle Complex Maintenance, Repair and Overhaul. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1184V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1184V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1184V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83446",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Financials Common Modules",
                    "text": "39383623"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials Common Modules.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financials Common Modules accessible data as well as  unauthorized access to critical data or complete access to all Oracle Financials Common Modules accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1320V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1320V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1320V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83447",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Bills of Material",
                    "text": "39384659"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Bills of Material accessible data as well as  unauthorized access to critical data or complete access to all Oracle Bills of Material accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-571V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-571V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-571V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83448",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Bills of Material",
                    "text": "39384662"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Bills of Material accessible data as well as  unauthorized access to critical data or complete access to all Oracle Bills of Material accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-571V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-571V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-571V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83449",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Bills of Material",
                    "text": "39384674"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material.  While the vulnerability is in Oracle Bills of Material, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Bills of Material accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Bills of Material. CVSS 3.1 Base Score 8.5 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-571V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-571V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-571V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83450",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Bills of Material",
                    "text": "39384679"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Bills of Material.  While the vulnerability is in Oracle Bills of Material, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-571V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-571V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-571V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83451",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Workbench",
                    "text": "39388981"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Workbench product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Workbench.  While the vulnerability is in Oracle Product Workbench, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Product Workbench. CVSS 3.1 Base Score 8.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1597V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1597V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1597V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83452",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Document Management and Collaboration",
                    "text": "39388983"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Document Management and Collaboration.  Successful attacks of this vulnerability can result in takeover of Oracle Document Management and Collaboration. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1314V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1314V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1314V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83453",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Document Management and Collaboration",
                    "text": "39389166"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Document Management and Collaboration.  Successful attacks of this vulnerability can result in takeover of Oracle Document Management and Collaboration. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1314V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1314V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1314V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83454",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Document Management and Collaboration",
                    "text": "39389309"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Document Management and Collaboration product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Document Management and Collaboration.  Successful attacks of this vulnerability can result in takeover of Oracle Document Management and Collaboration. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1314V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1314V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1314V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83455",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Demand Signal Repository",
                    "text": "39389722"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Demand Signal Repository accessible data as well as  unauthorized access to critical data or complete access to all Oracle Demand Signal Repository accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4546V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4546V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4546V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83456",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Demand Signal Repository",
                    "text": "39389724"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.  Successful attacks of this vulnerability can result in takeover of Oracle Demand Signal Repository. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4546V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4546V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4546V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83457",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Demand Signal Repository",
                    "text": "39389737"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Demand Signal Repository product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Demand Signal Repository.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Demand Signal Repository accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Demand Signal Repository. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4546V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4546V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4546V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83458",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Helidon",
                    "text": "39727443"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: JSON).  Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13972V-4.0.0-4.5.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13972V-4.0.0-4.5.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU357"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13972V-4.0.0-4.5.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83459",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Helidon",
                    "text": "39727446"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-media-multipart).  Supported versions that are affected are 3.0.0-3.2.20. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13972V-3.0.0-3.2.20"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13972V-3.0.0-3.2.20"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU357"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13972V-3.0.0-3.2.20"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83460",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Helidon",
                    "text": "39727447"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: LRA).  Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Helidon accessible data as well as  unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13972V-4.0.0-4.5.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13972V-4.0.0-4.5.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU357"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.5,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13972V-4.0.0-4.5.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83461",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Mobile Application Server",
                    "text": "39390173"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Mobile Application Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Mobile Application Server. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-995V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-995V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-995V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83462",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Mobile Application Server",
                    "text": "39390181"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application Server.  Successful attacks of this vulnerability can result in takeover of Oracle Mobile Application Server. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-995V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-995V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-995V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83463",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Mobile Application Server",
                    "text": "39390212"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Mobile Application Server executes to compromise Oracle Mobile Application Server.  Successful attacks of this vulnerability can result in takeover of Oracle Mobile Application Server. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-995V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-995V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-995V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83464",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Mobile Application Server",
                    "text": "39390233"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Mobile Application Server.  Successful attacks of this vulnerability can result in takeover of Oracle Mobile Application Server. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-995V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-995V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-995V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83465",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Mobile Application Server",
                    "text": "39390264"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Mobile Application Server product of Oracle E-Business Suite (component: MWA Terminal Server).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Mobile Application Server.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Mobile Application Server, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Mobile Application Server as well as  unauthorized update, insert or delete access to some of Oracle Mobile Application Server accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-995V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-995V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-995V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83477",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Work in Process",
                    "text": "39393287"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Workbenches).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Work in Process executes to compromise Oracle Work in Process.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Work in Process accessible data as well as  unauthorized access to critical data or complete access to all Oracle Work in Process accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-572V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-572V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-572V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83479",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Contracts",
                    "text": "39394392"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts.  Successful attacks of this vulnerability can result in takeover of Oracle Contracts. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-154V-12.2.14-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-154V-12.2.14-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-154V-12.2.14-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83480",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Helidon",
                    "text": "39727453"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: WebSocket).  Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Helidon. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13972V-4.0.0-4.5.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13972V-4.0.0-4.5.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU357"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13972V-4.0.0-4.5.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83481",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Contracts",
                    "text": "39394414"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts.  Successful attacks of this vulnerability can result in takeover of Oracle Contracts. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-154V-12.2.14-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-154V-12.2.14-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-154V-12.2.14-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83482",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Contracts",
                    "text": "39394438"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Contracts product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.14-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Contracts.  Successful attacks of this vulnerability can result in takeover of Oracle Contracts. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-154V-12.2.14-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-154V-12.2.14-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-154V-12.2.14-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83483",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Advanced Benefits",
                    "text": "39395739"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Advanced Benefits product of Oracle E-Business Suite (component: Self-serv What-if Analysis).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Advanced Benefits.  While the vulnerability is in Oracle Advanced Benefits, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Advanced Benefits. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-290V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-290V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-290V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83484",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle US Federal Human Resources",
                    "text": "39396534"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle US Federal Human Resources product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle US Federal Human Resources.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle US Federal Human Resources accessible data as well as  unauthorized read access to a subset of Oracle US Federal Human Resources accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-899V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-899V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-899V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83485",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Hub",
                    "text": "39397381"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub.  While the vulnerability is in Oracle Product Hub, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1313V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1313V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1313V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83486",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Hub",
                    "text": "39397395"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub.  While the vulnerability is in Oracle Product Hub, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1313V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1313V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1313V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83487",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Hub",
                    "text": "39397418"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Item Catalog).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub.  While the vulnerability is in Oracle Product Hub, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1313V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1313V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1313V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83488",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Helidon",
                    "text": "39727469"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-microprofile-security).  Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Helidon accessible data as well as  unauthorized read access to a subset of Helidon accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13972V-4.0.0-4.5.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13972V-4.0.0-4.5.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU357"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13972V-4.0.0-4.5.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83489",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Origination",
                    "text": "39737088"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Origination product of Oracle Financial Services Applications (component: Onboarding Batch Processes).  Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Origination.  Successful attacks of this vulnerability can result in takeover of Oracle Banking Origination. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14325V-14.5.0.0.0-14.9.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14325V-14.5.0.0.0-14.9.0.0.0"
                    ],
                    "url": "https://support.oracle.com"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14325V-14.5.0.0.0-14.9.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83490",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iRecruitment",
                    "text": "39397699"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iRecruitment.  While the vulnerability is in Oracle iRecruitment, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle iRecruitment accessible data as well as  unauthorized update, insert or delete access to some of Oracle iRecruitment accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1193V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1193V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1193V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-83491",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iRecruitment",
                    "text": "39397713"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle iRecruitment executes to compromise Oracle iRecruitment.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle iRecruitment accessible data as well as  unauthorized access to critical data or complete access to all Oracle iRecruitment accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1193V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1193V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1193V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87124",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle iRecruitment",
                    "text": "39397852"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iRecruitment.  While the vulnerability is in Oracle iRecruitment, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle iRecruitment accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1193V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1193V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1193V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87125",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Financials for Asia/Pacific",
                    "text": "39398008"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Financials for Asia/Pacific product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials for Asia/Pacific.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Financials for Asia/Pacific accessible data as well as  unauthorized access to critical data or complete access to all Oracle Financials for Asia/Pacific accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Financials for Asia/Pacific. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-989V-12.2.8-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-989V-12.2.8-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-989V-12.2.8-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87126",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Report Manager",
                    "text": "39415570"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Report Manager product of Oracle E-Business Suite (component: Reports Security).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Report Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Report Manager accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Report Manager. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-777V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-777V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-777V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87127",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Purchasing",
                    "text": "39428764"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing).  Supported versions that are affected are 12.2.10-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing.  While the vulnerability is in Oracle Purchasing, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-502V-12.2.10-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-502V-12.2.10-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-502V-12.2.10-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87128",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39468867"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87129",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39468872"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87130",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39468989"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87131",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39469025"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87132",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39469036"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87133",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39469045"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87134",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39469057"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Hyperion Data Relationship Management.  While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87135",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39469072"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87136",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39469087"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87137",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39469120"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87138",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39469168"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via SOAP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87139",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39469185"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87140",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39469195"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87141",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39469227"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87142",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39469235"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Data Relationship Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87143",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39469260"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87144",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39469267"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87145",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39469277"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data as well as  unauthorized read access to a subset of Oracle Hyperion Data Relationship Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87146",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39469309"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87147",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39469456"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  While the vulnerability is in Oracle Hyperion Data Relationship Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87148",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Data Relationship Management",
                    "text": "39469708"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Data Relationship Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4375V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4375V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4375V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87149",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Contract Lifecycle Management for Public Sector",
                    "text": "39487739"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Award/PO).  Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract Lifecycle Management for Public Sector.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Contract Lifecycle Management for Public Sector accessible data as well as  unauthorized update, insert or delete access to some of Oracle Contract Lifecycle Management for Public Sector accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8759V-12.2.8-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8759V-12.2.8-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8759V-12.2.8-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87150",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Bills of Material",
                    "text": "39491585"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material.  Successful attacks of this vulnerability can result in takeover of Oracle Bills of Material. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-571V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-571V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-571V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87151",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Bills of Material",
                    "text": "39491894"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Setup Workbench).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Bills of Material.  While the vulnerability is in Oracle Bills of Material, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Bills of Material accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-571V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-571V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-571V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87152",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Installed Base",
                    "text": "39492073"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Installed Base accessible data as well as  unauthorized access to critical data or complete access to all Oracle Installed Base accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1118V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1118V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1118V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87153",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Hub",
                    "text": "39492595"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Hub accessible data as well as  unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1313V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1313V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1313V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87154",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Hub",
                    "text": "39492600"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Product Hub accessible data as well as  unauthorized access to critical data or complete access to all Oracle Product Hub accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1313V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1313V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1313V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87155",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Hub",
                    "text": "39493364"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub.  Successful attacks of this vulnerability can result in takeover of Oracle Product Hub. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1313V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1313V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1313V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87156",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Product Hub",
                    "text": "39493377"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Product Hub.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Product Hub accessible data as well as  unauthorized update, insert or delete access to some of Oracle Product Hub accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1313V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1313V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1313V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87157",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Order Management",
                    "text": "39493786"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Product Diagnostic Tools).  Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Order Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Order Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-497V-12.2.4-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-497V-12.2.4-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-497V-12.2.4-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87158",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Order Management",
                    "text": "39493960"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Order Management product of Oracle E-Business Suite (component: Enterprise Command Center).   The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Order Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Order Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Order Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-497V-V16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-497V-V16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-497V-V16"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87159",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HRMS (India)",
                    "text": "39495073"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (India).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle HRMS (India) accessible data as well as  unauthorized access to critical data or complete access to all Oracle HRMS (India) accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1557V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1557V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1557V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87160",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HRMS (India)",
                    "text": "39496126"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle HRMS (India).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle HRMS (India) accessible data as well as  unauthorized update, insert or delete access to some of Oracle HRMS (India) accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1557V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1557V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1557V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87161",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle HRMS (India)",
                    "text": "39496138"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle HRMS (India) product of Oracle E-Business Suite (component: Internal Operations).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle HRMS (India).  While the vulnerability is in Oracle HRMS (India), attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle HRMS (India) accessible data as well as  unauthorized update, insert or delete access to some of Oracle HRMS (India) accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-1557V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-1557V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-1557V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87162",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Contract Lifecycle Management for Public Sector",
                    "text": "39496349"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Award/PO).  Supported versions that are affected are 12.2.13-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract Lifecycle Management for Public Sector.  Successful attacks of this vulnerability can result in takeover of Oracle Contract Lifecycle Management for Public Sector. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8759V-12.2.13-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8759V-12.2.13-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8759V-12.2.13-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87163",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Purchasing",
                    "text": "39496382"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing.  Successful attacks of this vulnerability can result in takeover of Oracle Purchasing. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-502V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-502V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-502V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87164",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Banking Branch",
                    "text": "39801508"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Banking Branch product of Oracle Financial Services Applications (component: Reports).  Supported versions that are affected are 14.5.0.0.0-14.9.0.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Banking Branch.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Banking Branch, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Banking Branch. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14324V-14.5.0.0.0-14.9.0.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14324V-14.5.0.0.0-14.9.0.0.0"
                    ],
                    "url": "https://support.oracle.com"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-14324V-14.5.0.0.0-14.9.0.0.0"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87165",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Contract Lifecycle Management for Public Sector",
                    "text": "39496463"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: ECC For Award and IDV).   The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract Lifecycle Management for Public Sector.  Successful attacks of this vulnerability can result in takeover of Oracle Contract Lifecycle Management for Public Sector. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8759V-V16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8759V-V16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8759V-V16"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87166",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Purchasing",
                    "text": "39496509"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Purchasing accessible data as well as  unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-502V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-502V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-502V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87167",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Purchasing",
                    "text": "39496774"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing).  Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Purchasing accessible data as well as  unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-502V-12.2.11-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-502V-12.2.11-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-502V-12.2.11-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87168",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Purchasing",
                    "text": "39496819"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: G-Invoicing).  Supported versions that are affected are 12.2.10-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Purchasing accessible data as well as  unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-502V-12.2.10-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-502V-12.2.10-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-502V-12.2.10-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87169",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Contract Lifecycle Management for Public Sector",
                    "text": "39497021"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Wage Determination Online).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Contract Lifecycle Management for Public Sector.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Contract Lifecycle Management for Public Sector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Contract Lifecycle Management for Public Sector accessible data as well as  unauthorized read access to a subset of Oracle Contract Lifecycle Management for Public Sector accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8759V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8759V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8759V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87170",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506104"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87171",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506107"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Hyperion Financial Management.  While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87172",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506114"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.9,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87173",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506119"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87174",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506123"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87175",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506126"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87176",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506131"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87177",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506219"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87178",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506222"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management.  While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.7 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87179",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506229"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87180",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506235"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87181",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506241"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87182",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506247"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87183",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506252"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87184",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506255"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via SQL to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87185",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506259"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87186",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506264"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.6,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87187",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506268"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87188",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506277"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.8,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87189",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506281"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Hyperion Financial Management.  While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87190",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506285"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87191",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506291"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87192",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506295"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87193",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506311"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87194",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506318"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87195",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506323"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87196",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506327"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87197",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506330"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87198",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506336"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87199",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506343"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87200",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506348"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87201",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506363"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87202",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506366"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87203",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506372"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87204",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506397"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87205",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506405"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87206",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506415"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87207",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506423"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87208",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506432"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87209",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506442"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87210",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506460"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87211",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506477"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87212",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506482"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SQL to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87213",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506493"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87214",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506500"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87215",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506505"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87216",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506531"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87217",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506540"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87218",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506550"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87219",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506554"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87220",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506557"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management as well as  unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87221",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506562"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87222",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506567"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87223",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506580"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 9.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 9.1,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87224",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506581"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87225",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506587"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87226",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506594"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87227",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506596"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87228",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506609"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87229",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506617"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized read access to a subset of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87230",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506620"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 10.0,
                        "baseSeverity": "CRITICAL",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87231",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506624"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87232",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506633"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87233",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506637"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.6 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87234",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506648"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87235",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506656"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87236",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506661"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87237",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506668"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87238",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506671"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87239",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506781"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87240",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39506922"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87241",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39507189"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87242",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39507194"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87243",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39507199"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  While the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 8.0 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87244",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39507252"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87245",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39507334"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.0,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87246",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39507339"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87247",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39507343"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87248",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39507437"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Hyperion Financial Management executes to compromise Oracle Hyperion Financial Management.  Successful attacks of this vulnerability can result in takeover of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.7,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87249",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39507463"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Financial Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Financial Management. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87250",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Hyperion Financial Management",
                    "text": "39507495"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hyperion Financial Management, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4390V-11.2.26.0.000"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4390V-11.2.26.0.000"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA812"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4390V-11.2.26.0.000"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87252",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39529376"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server).   The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile PLM executes to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile PLM accessible data as well as  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4461V-9.3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.8,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4461V-9.3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87253",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39529378"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Web Client).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data as well as  unauthorized read access to a subset of Oracle Agile PLM accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4461V-9.3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4461V-9.3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87254",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39529390"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments).   The supported version that is affected is 9.3.6. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in takeover of Oracle Agile PLM. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4461V-9.3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4461V-9.3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87256",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39529427"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  While the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4461V-9.3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4461V-9.3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87257",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39529636"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: SDK).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  While the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4461V-9.3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4461V-9.3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87258",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39529642"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Folders, Files & Attachments).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Agile PLM, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data as well as  unauthorized update, insert or delete access to some of Oracle Agile PLM accessible data. CVSS 3.1 Base Score 7.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4461V-9.3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4461V-9.3.6"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87259",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Engineering Data Management",
                    "text": "39616265"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface).   The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management.  While the vulnerability is in Oracle Agile Engineering Data Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 8.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4436V-6.2.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4436V-6.2.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.4,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4436V-6.2.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87260",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Engineering Data Management",
                    "text": "39616266"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface).   The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Agile Engineering Data Management accessible data as well as  unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4436V-6.2.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4436V-6.2.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4436V-6.2.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87261",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Engineering Data Management",
                    "text": "39616298"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface).   The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management.  While the vulnerability is in Oracle Agile Engineering Data Management, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 7.3 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4436V-6.2.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4436V-6.2.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.3,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4436V-6.2.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87262",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile Engineering Data Management",
                    "text": "39616299"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface).   The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Agile Engineering Data Management executes to compromise Oracle Agile Engineering Data Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile Engineering Data Management accessible data as well as  unauthorized update, insert or delete access to some of Oracle Agile Engineering Data Management accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4436V-6.2.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4436V-6.2.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4436V-6.2.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87264",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of PeopleSoft Enterprise PeopleTools",
                    "text": "39651728"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Integration Broker).  Supported versions that are affected are 8.61-8.63. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  While the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.1 Base Score 7.7 (Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-5085V-8.61-8.63"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-5085V-8.61-8.63"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU354"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.7,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-5085V-8.61-8.63"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87265",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Purchasing",
                    "text": "39657553"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Purchasing product of Oracle E-Business Suite (component: Other issue).  Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Purchasing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Purchasing accessible data as well as  unauthorized access to critical data or complete access to all Oracle Purchasing accessible data. CVSS 3.1 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-502V-12.2.3-12.2.15"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-502V-12.2.3-12.2.15"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=KA923"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-502V-12.2.3-12.2.15"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87266",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Agile PLM",
                    "text": "39740080"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain (component: Application Server).   The supported version that is affected is 9.3.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Agile PLM.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Agile PLM accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Agile PLM. CVSS 3.1 Base Score 8.2 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-4461V-9.3.6"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-4461V-9.3.6"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU355"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.2,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-4461V-9.3.6"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Myeonghun Pak and Seongmin Kim"
                    ],
                    "organization": "Team SaturnX"
                }
            ],
            "cve": "CVE-2026-87267",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39850976"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows low privileged attacker with network access via RDP to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 5.3,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "James Forshaw"
                    ]
                }
            ],
            "cve": "CVE-2026-87268",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39859112"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox.  Note: This vulnerability applies to Windows host only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "James Forshaw"
                    ]
                }
            ],
            "cve": "CVE-2026-87269",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39859123"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox.  Note: This vulnerability applies to Windows host only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "James Forshaw"
                    ]
                }
            ],
            "cve": "CVE-2026-87270",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39859127"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox.  Note: This vulnerability applies to Windows host only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "James Forshaw"
                    ]
                }
            ],
            "cve": "CVE-2026-87271",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39859133"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox.  Note: This vulnerability applies to Windows host only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "James Forshaw"
                    ]
                }
            ],
            "cve": "CVE-2026-87272",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39859139"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.8,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Diego Palacios"
                    ]
                }
            ],
            "cve": "CVE-2026-87273",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39861072"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.6,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Nathan Tsai"
                    ]
                }
            ],
            "cve": "CVE-2026-87274",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39861574"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 4.4 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.4,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Khalilov M (3ntr0py1337)"
                    ]
                }
            ],
            "cve": "CVE-2026-87275",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39866253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 4.6 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.6,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Tristan Madani"
                    ],
                    "organization": "Talence Security"
                }
            ],
            "cve": "CVE-2026-87276",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39877531"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Wei Ming Tan"
                    ]
                }
            ],
            "cve": "CVE-2026-87277",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39904793"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows unauthenticated attacker with network access via RDP to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Wei Ming Tan"
                    ]
                }
            ],
            "cve": "CVE-2026-87278",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39904806"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as  unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Kirishiki Yudai"
                    ]
                }
            ],
            "cve": "CVE-2026-87279",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39916840"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as  unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.1,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Nebula Security"
                    ]
                }
            ],
            "cve": "CVE-2026-87280",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39932372"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 4.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 4.2,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Nebula Security"
                    ]
                }
            ],
            "cve": "CVE-2026-87281",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39932382"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 3.2 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.2,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Nebula Security"
                    ]
                }
            ],
            "cve": "CVE-2026-87282",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39932397"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.0,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Nebula Security"
                    ]
                }
            ],
            "cve": "CVE-2026-87283",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39932405"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.0,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Nebula Security"
                    ]
                }
            ],
            "cve": "CVE-2026-87284",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39932412"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 3.2 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 3.2,
                        "baseSeverity": "LOW",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:L",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Nebula Security"
                    ]
                }
            ],
            "cve": "CVE-2026-87285",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle VM VirtualBox",
                    "text": "39932415"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core).   The supported version that is affected is 7.2.16. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 6.0 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-8370V-7.2.16"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-8370V-7.2.16"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU351"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 6.0,
                        "baseSeverity": "MEDIUM",
                        "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-8370V-7.2.16"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87286",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GraalVM",
                    "text": "39764105"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler).   The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM.  Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13497V-25.0.4.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13497V-25.0.4.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU349"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13497V-25.0.4.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87287",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GraalVM",
                    "text": "39757021"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler).   The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM.  Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13497V-25.0.4.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13497V-25.0.4.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU349"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13497V-25.0.4.1"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-87288",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle GraalVM",
                    "text": "39769955"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle GraalVM product of Oracle Java SE (component: Compiler).   The supported version that is affected is Oracle GraalVM: 25.0.4.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle GraalVM.  Successful attacks of this vulnerability can result in takeover of Oracle GraalVM. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13497V-25.0.4.1"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13497V-25.0.4.1"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU349"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 8.1,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13497V-25.0.4.1"
                    ]
                }
            ]
        },
        {
            "acknowledgments": [
                {
                    "names": [
                        "Nhat Anh Vu"
                    ]
                }
            ],
            "cve": "CVE-2026-87289",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Helidon",
                    "text": "39838468"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver-static-content).  Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Helidon.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-13972V-4.0.0-4.5.4"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-13972V-4.0.0-4.5.4"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU357"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-13972V-4.0.0-4.5.4"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-8857",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39879253"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (MediaWiki)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Communications Unified Assurance, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Unified Assurance accessible data as well as  unauthorized read access to a subset of Oracle Communications Unified Assurance accessible data.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        },
        {
            "cve": "CVE-2026-9563",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Service Catalog and Design",
                    "text": "39830877"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Service Catalog and Design product of Oracle Communications (component: Third Party Patch (Eclipse Parsson)).  Supported versions that are affected are 8.0-8.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Catalog and Design.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Catalog and Design. CVSS 3.1 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-2283V-8.0-8.3"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-2283V-8.0-8.3"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU344"
                }
            ],
            "scores": [
                {
                    "cvss_v3": {
                        "baseScore": 7.5,
                        "baseSeverity": "HIGH",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
                        "version": "3.1"
                    },
                    "products": [
                        "P-2283V-8.0-8.3"
                    ]
                }
            ]
        },
        {
            "cve": "CVE-2026-9698",
            "ids": [
                {
                    "system_name": "Oracle Bug ID of Oracle Communications Unified Assurance",
                    "text": "39868962"
                }
            ],
            "notes": [
                {
                    "category": "description",
                    "text": "Vulnerability in the Oracle Communications Unified Assurance product of Oracle Communications (component: Core (DBI)).  Supported versions that are affected are 6.1.1-7.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Unified Assurance.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Unified Assurance accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Unified Assurance.",
                    "title": "Vulnerability Description"
                }
            ],
            "product_status": {
                "known_affected": [
                    "P-14597V-6.1.1-7.0.0"
                ]
            },
            "remediations": [
                {
                    "category": "vendor_fix",
                    "details": "Oracle customers with valid support contracts",
                    "product_ids": [
                        "P-14597V-6.1.1-7.0.0"
                    ],
                    "url": "https://support.oracle.com/support/?documentId=CPU343"
                }
            ]
        }
    ]
}