<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1687073.xsl"?>
<?xml-stylesheet type="text/css" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1686935.css"?>
<cvrf:cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle Critical Patch Update Advisory - October 2013 - Beta Oracle CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle Critical Patch Update Advisory</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>CPUOct2013</ID>
      </Identification>
      <Status>Final</Status>
      <Version>1.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>1.0</Number>
            <Date>2013-10-15T13:00:00-07:00</Date>
            <Description>Initial Distribution</Description>
         </Revision>
      </RevisionHistory>
      <InitialReleaseDate>2013-10-15T13:00:00-07:00</InitialReleaseDate>
      <CurrentReleaseDate>2013-10-15T13:00:00-07:00</CurrentReleaseDate>
   </DocumentTracking>
   <DocumentNotes>
      <Note Audience="All" Ordinal="1" Title="Summary" Type="Summary" xml:lang="en">This document contains descriptions of Oracle product security vulnerabilities which have had fixes released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including fix distribution information can be found at the Oracle sites referenced in this document.</Note>
   </DocumentNotes>
   <DocumentDistribution>This document is published at: http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1865183.xml</DocumentDistribution>
   <DocumentReferences>
      <Reference Type="External">
         <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
   <Acknowledgments>
      <Acknowledgment>
         <Name>Adam Gowdiak</Name>
         <Organization>Security Explorations</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Adam Willard</Name>
         <Organization>Foreground Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Adi Ludmer</Name>
         <Organization>McAfee Security Research</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ajinkya Patil</Name>
         <Organization>AVsecurity.in</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alex  Kouzemtchenko</Name>
         <Organization>CERT/CC</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alex Rajan</Name>
         <Organization>Network Intelligence (Alex Rajan)</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alexander Polyakov</Name>
         <Organization>ERPScan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alexander Tlyapov</Name>
         <Organization>Positive Technologies</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alexey Osipov</Name>
         <Organization>Positive Technologies</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alexey Tyurin</Name>
         <Organization>ERPScan (Digital Security Research Group)</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alok Saurabh</Name>
         <Organization>Alok Saurabh</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Anagha Devale-Vartak</Name>
         <Organization>AVsecurity.in</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Andrea Micalizzi</Name>
         <Organization>HP's Zero Day Initiative</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Andrew Davies</Name>
         <Organization>NCC Group</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ben Murphy</Name>
         <Organization>HP's Zero Day Initiative</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>CERT/CC</Name>
         <Organization>CERT/CC</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Chris Ries via the Exodus Intelligence Program</Name>
         <Organization>Exodus Intelligence</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Daniel Fernández Bleda</Name>
         <Organization>Internet Security Auditors, S.L.</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Danish Tariq</Name>
         <Organization>Danish Tariq</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Dave Bryant</Name>
         <Organization>Orion Health</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Dmitry Sklyarov</Name>
         <Organization>Positive Technologies</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ehraz Ahmed</Name>
         <Organization>Ehraz Ahmed</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Esteban Martinez Fayo</Name>
         <Organization>Application Security, Inc.</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Faisal ait hamou</Name>
         <Organization>Faisal ait hamou</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>HUAWEI PSIRT</Name>
         <Organization>HUAWEI PSIRT</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Hamza Gheld</Name>
         <Organization>Hamza Gheld</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Harsha Vardhan Boppana</Name>
         <Organization>Harsha Vardhan Boppana</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>James Forshaw</Name>
         <Organization>Context Information Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jatinpreet Singh</Name>
         <Organization>Jatinpreet Singh</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jeroen Frijters</Name>
         <Organization>Jeroen Frijters</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jigar Thakkar</Name>
         <Organization>Jigar Thakkar</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jon Passki</Name>
         <Organization>CERT/CC</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Juraj Somorovsky</Name>
         <Organization>Ruhr-University Bochum</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Kamil Sevi</Name>
         <Organization>Kamil Sevi</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Koutrouss Naddara</Name>
         <Organization>Kotros Nadara</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mahadev Subedi</Name>
         <Organization>Mahadev Subedi</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mahesh Darji</Name>
         <Organization>SRIMCA</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Manjot Singh</Name>
         <Organization>Manjot Singh</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Muhammad Ahmed Siddiqui</Name>
         <Organization>Muhammad Ahmed Siddiqui</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Narendra Bhati</Name>
         <Organization>Narendra Bhati</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Osanda Malith Jayathissa</Name>
         <Organization>Osanda Malith Jayathissa</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Qinglin Jiang</Name>
         <Organization>Application Security, Inc.</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ravi Chandroliya</Name>
         <Organization>Ravi Chandroliya</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ravikumar R. Paghdal</Name>
         <Organization>SRIMCA</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Riaz Ebrahim</Name>
         <Organization>Riaz Ebrahim</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Rohan Stelling</Name>
         <Organization>BAE Systems Detica</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sam Thomas</Name>
         <Organization>Pentest Limited</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Simone Memoli</Name>
         <Organization>Simone Memoli</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>SimranJeet Singh</Name>
         <Organization>SimranJeet Singh</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sunil Dadhich</Name>
         <Organization>Sunil Dadhich</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Timur Yunusov</Name>
         <Organization>Positive Technologies</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Tom Parker</Name>
         <Organization>Orion Health</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Travis Emmert</Name>
         <Organization>iDefense</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Vinesh N. Redkar</Name>
         <Organization>Vinesh N. Redkar</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Vitaliy Toropov via the Exodus Intelligence Program</Name>
         <Organization>Exodus Intelligence</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Will Dormann</Name>
         <Organization>CERT/CC</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Yasir Altaf Zargar</Name>
         <Organization>Yasir Altaf Zargar</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Yuki Chen</Name>
         <Organization>Trend Micro</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Yury Maryshev</Name>
         <Organization>Positive Technologies</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>wcypierre</Name>
         <Organization>wcypierre</Organization>
      </Acknowledgment>
   </Acknowledgments>
   <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Name="Oracle" Type="Vendor">
         <Branch Name="Oracle Database Server" Type="Product Family">
            <Branch Name="Oracle Database" Type="Product Name">
               <Branch Name="-" Type="Product Version">
                  <FullProductName ProductID="P-5V--">Oracle Database Version -</FullProductName>
               </Branch>
               <Branch Name="11.1.0.7" Type="Product Version">
                  <FullProductName ProductID="P-5V-11.1.0.7">Oracle Database Version 11.1.0.7</FullProductName>
               </Branch>
               <Branch Name="11.2.0.2" Type="Product Version">
                  <FullProductName ProductID="P-5V-11.2.0.2">Oracle Database Version 11.2.0.2</FullProductName>
               </Branch>
               <Branch Name="11.2.0.3" Type="Product Version">
                  <FullProductName ProductID="P-5V-11.2.0.3">Oracle Database Version 11.2.0.3</FullProductName>
               </Branch>
               <Branch Name="12.1.0.1" Type="Product Version">
                  <FullProductName ProductID="P-5V-12.1.0.1">Oracle Database Version 12.1.0.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle E-Business Suite" Type="Product Family">
            <Branch Name="Applications Technology Stack" Type="Product Name">
               <Branch Name="12.1" Type="Product Version">
                  <FullProductName ProductID="P-1745V-12.1">Applications Technology Stack Version 12.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Enterprise Manager Grid Control" Type="Product Family">
            <Branch Name="Enterprise Manager for Oracle Database" Type="Product Name">
               <Branch Name="11.1.0.1 EM DB Control: 11.1.0.7" Type="Product Version">
                  <FullProductName ProductID="P-1366V-11.1.0.1 EM DB Control: 11.1.0.7">Enterprise Manager for Oracle Database Version 11.1.0.1 EM DB Control: 11.1.0.7</FullProductName>
               </Branch>
               <Branch Name="11.1.0.1EM DB Control: 11.1.0.7" Type="Product Version">
                  <FullProductName ProductID="P-1366V-11.1.0.1EM DB Control: 11.1.0.7">Enterprise Manager for Oracle Database Version 11.1.0.1EM DB Control: 11.1.0.7</FullProductName>
               </Branch>
               <Branch Name="11.2.0.2" Type="Product Version">
                  <FullProductName ProductID="P-1366V-11.2.0.2">Enterprise Manager for Oracle Database Version 11.2.0.2</FullProductName>
               </Branch>
               <Branch Name="11.2.0.3 EM Plugin for DB: 12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-1366V-11.2.0.3 EM Plugin for DB: 12.1.0.2">Enterprise Manager for Oracle Database Version 11.2.0.3 EM Plugin for DB: 12.1.0.2</FullProductName>
               </Branch>
               <Branch Name="11.2.0.3EM Plugin for DB: 12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-1366V-11.2.0.3EM Plugin for DB: 12.1.0.2">Enterprise Manager for Oracle Database Version 11.2.0.3EM Plugin for DB: 12.1.0.2</FullProductName>
               </Branch>
               <Branch Name="12.1.0.3" Type="Product Version">
                  <FullProductName ProductID="P-1366V-12.1.0.3">Enterprise Manager for Oracle Database Version 12.1.0.3</FullProductName>
               </Branch>
               <Branch Name="12.1.0.4" Type="Product Version">
                  <FullProductName ProductID="P-1366V-12.1.0.4">Enterprise Manager for Oracle Database Version 12.1.0.4</FullProductName>
               </Branch>
               <Branch Name="EM Base Platform: 10.2.0.5" Type="Product Version">
                  <FullProductName ProductID="P-1366V-EM Base Platform: 10.2.0.5">Enterprise Manager for Oracle Database Version EM Base Platform: 10.2.0.5</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Financial Services Software" Type="Product Family">
            <Branch Name="FLEXCUBE Private Banking" Type="Product Name">
               <Branch Name="1.7" Type="Product Version">
                  <FullProductName ProductID="P-9110V-1.7">FLEXCUBE Private Banking Version 1.7</FullProductName>
               </Branch>
               <Branch Name="12.0.1" Type="Product Version">
                  <FullProductName ProductID="P-9110V-12.0.1">FLEXCUBE Private Banking Version 12.0.1</FullProductName>
               </Branch>
               <Branch Name="2.0" Type="Product Version">
                  <FullProductName ProductID="P-9110V-2.0">FLEXCUBE Private Banking Version 2.0</FullProductName>
               </Branch>
               <Branch Name="2.0.1" Type="Product Version">
                  <FullProductName ProductID="P-9110V-2.0.1">FLEXCUBE Private Banking Version 2.0.1</FullProductName>
               </Branch>
               <Branch Name="2.2.0.1" Type="Product Version">
                  <FullProductName ProductID="P-9110V-2.2.0.1">FLEXCUBE Private Banking Version 2.2.0.1</FullProductName>
               </Branch>
               <Branch Name="3.0" Type="Product Version">
                  <FullProductName ProductID="P-9110V-3.0">FLEXCUBE Private Banking Version 3.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Fusion Middleware" Type="Product Family">
            <Branch Name="Portal" Type="Product Name">
               <Branch Name="11.1.1.6.0" Type="Product Version">
                  <FullProductName ProductID="P-96V-11.1.1.6.0">Portal Version 11.1.1.6.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="JDeveloper" Type="Product Name">
               <Branch Name="11.1.2.3.0" Type="Product Version">
                  <FullProductName ProductID="P-807V-11.1.2.3.0">JDeveloper Version 11.1.2.3.0</FullProductName>
               </Branch>
               <Branch Name="11.1.2.4.0" Type="Product Version">
                  <FullProductName ProductID="P-807V-11.1.2.4.0">JDeveloper Version 11.1.2.4.0</FullProductName>
               </Branch>
               <Branch Name="12.1.2.0.0" Type="Product Version">
                  <FullProductName ProductID="P-807V-12.1.2.0.0">JDeveloper Version 12.1.2.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Security Service" Type="Product Name">
               <Branch Name="11.1.1.7 Forms: 11.1.2.1" Type="Product Version">
                  <FullProductName ProductID="P-991V-11.1.1.7 Forms: 11.1.2.1">Security Service Version 11.1.1.7 Forms: 11.1.2.1</FullProductName>
               </Branch>
               <Branch Name="11.1.1.7 Forms: 11.1.2.1 OHS: 12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-991V-11.1.1.7 Forms: 11.1.2.1 OHS: 12.1.2">Security Service Version 11.1.1.7 Forms: 11.1.2.1 OHS: 12.1.2</FullProductName>
               </Branch>
               <Branch Name="FMW: 11.1.1.6" Type="Product Version">
                  <FullProductName ProductID="P-991V-FMW: 11.1.1.6">Security Service Version FMW: 11.1.1.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Web Cache" Type="Product Name">
               <Branch Name="11.1.1.6" Type="Product Version">
                  <FullProductName ProductID="P-1059V-11.1.1.6">Web Cache Version 11.1.1.6</FullProductName>
               </Branch>
               <Branch Name="11.1.1.7" Type="Product Version">
                  <FullProductName ProductID="P-1059V-11.1.1.7">Web Cache Version 11.1.1.7</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Containers for J2EE" Type="Product Name">
               <Branch Name="10.1.3.5.0" Type="Product Version">
                  <FullProductName ProductID="P-1270V-10.1.3.5.0">Containers for J2EE Version 10.1.3.5.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Web Services" Type="Product Name">
               <Branch Name="10.1.3.5.0" Type="Product Version">
                  <FullProductName ProductID="P-1271V-10.1.3.5.0">Web Services Version 10.1.3.5.0</FullProductName>
               </Branch>
               <Branch Name="11.1.1.6.0" Type="Product Version">
                  <FullProductName ProductID="P-1271V-11.1.1.6.0">Web Services Version 11.1.1.6.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Identity Manager" Type="Product Name">
               <Branch Name="11.1.2.0.0" Type="Product Version">
                  <FullProductName ProductID="P-1980V-11.1.2.0.0">Identity Manager Version 11.1.2.0.0</FullProductName>
               </Branch>
               <Branch Name="11.1.2.1.0" Type="Product Version">
                  <FullProductName ProductID="P-1980V-11.1.2.1.0">Identity Manager Version 11.1.2.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebCenter Content" Type="Product Name">
               <Branch Name="10.1.3.5.1" Type="Product Version">
                  <FullProductName ProductID="P-2271V-10.1.3.5.1">WebCenter Content Version 10.1.3.5.1</FullProductName>
               </Branch>
               <Branch Name="11.1.1.6.0" Type="Product Version">
                  <FullProductName ProductID="P-2271V-11.1.1.6.0">WebCenter Content Version 11.1.1.6.0</FullProductName>
               </Branch>
               <Branch Name="11.1.1.7.0" Type="Product Version">
                  <FullProductName ProductID="P-2271V-11.1.1.7.0">WebCenter Content Version 11.1.1.7.0</FullProductName>
               </Branch>
               <Branch Name="11.1.1.8.0" Type="Product Version">
                  <FullProductName ProductID="P-2271V-11.1.1.8.0">WebCenter Content Version 11.1.1.8.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Outside In Technology" Type="Product Name">
               <Branch Name="8.4.0" Type="Product Version">
                  <FullProductName ProductID="P-2276V-8.4.0">Outside In Technology Version 8.4.0</FullProductName>
               </Branch>
               <Branch Name="8.4.1" Type="Product Version">
                  <FullProductName ProductID="P-2276V-8.4.1">Outside In Technology Version 8.4.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebLogic Server" Type="Product Name">
               <Branch Name="10.3.6.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-10.3.6.0">WebLogic Server Version 10.3.6.0</FullProductName>
               </Branch>
               <Branch Name="12.1.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.1.1.0">WebLogic Server Version 12.1.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Access Manager" Type="Product Name">
               <Branch Name="11.1.1.5.0" Type="Product Version">
                  <FullProductName ProductID="P-5565V-11.1.1.5.0">Access Manager Version 11.1.1.5.0</FullProductName>
               </Branch>
               <Branch Name="11.1.2.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5565V-11.1.2.0.0">Access Manager Version 11.1.2.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="GlassFish Server" Type="Product Name">
               <Branch Name="2.1.1" Type="Product Version">
                  <FullProductName ProductID="P-8493V-2.1.1">GlassFish Server Version 2.1.1</FullProductName>
               </Branch>
               <Branch Name="3.0.1" Type="Product Version">
                  <FullProductName ProductID="P-8493V-3.0.1">GlassFish Server Version 3.0.1</FullProductName>
               </Branch>
               <Branch Name="3.1.2" Type="Product Version">
                  <FullProductName ProductID="P-8493V-3.1.2">GlassFish Server Version 3.1.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Identity Analytics" Type="Product Name">
               <Branch Name="5.0" Type="Product Version">
                  <FullProductName ProductID="P-8522V-5.0">Identity Analytics Version 5.0</FullProductName>
               </Branch>
               <Branch Name="Oracle Identity Analytics 11.1.1.5" Type="Product Version">
                  <FullProductName ProductID="P-8522V-Oracle Identity Analytics 11.1.1.5">Identity Analytics Version Oracle Identity Analytics 11.1.1.5</FullProductName>
               </Branch>
               <Branch Name="Sun Role Manager 4.1" Type="Product Version">
                  <FullProductName ProductID="P-8522V-Sun Role Manager 4.1">Identity Analytics Version Sun Role Manager 4.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Industry Applications" Type="Product Family">
            <Branch Name="Retail Invoice Matching" Type="Product Name">
               <Branch Name="10.2" Type="Product Version">
                  <FullProductName ProductID="P-1810V-10.2">Retail Invoice Matching Version 10.2</FullProductName>
               </Branch>
               <Branch Name="11.0" Type="Product Version">
                  <FullProductName ProductID="P-1810V-11.0">Retail Invoice Matching Version 11.0</FullProductName>
               </Branch>
               <Branch Name="12.0" Type="Product Version">
                  <FullProductName ProductID="P-1810V-12.0">Retail Invoice Matching Version 12.0</FullProductName>
               </Branch>
               <Branch Name="12.0IN" Type="Product Version">
                  <FullProductName ProductID="P-1810V-12.0IN">Retail Invoice Matching Version 12.0IN</FullProductName>
               </Branch>
               <Branch Name="12.1" Type="Product Version">
                  <FullProductName ProductID="P-1810V-12.1">Retail Invoice Matching Version 12.1</FullProductName>
               </Branch>
               <Branch Name="13.0" Type="Product Version">
                  <FullProductName ProductID="P-1810V-13.0">Retail Invoice Matching Version 13.0</FullProductName>
               </Branch>
               <Branch Name="13.1" Type="Product Version">
                  <FullProductName ProductID="P-1810V-13.1">Retail Invoice Matching Version 13.1</FullProductName>
               </Branch>
               <Branch Name="13.2" Type="Product Version">
                  <FullProductName ProductID="P-1810V-13.2">Retail Invoice Matching Version 13.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Health Sciences Product" Type="Product Name">
               <Branch Name="4.5 SP3" Type="Product Version">
                  <FullProductName ProductID="P-9132V-4.5 SP3">Health Sciences Product Version 4.5 SP3</FullProductName>
               </Branch>
               <Branch Name="4.5 SP3a-k" Type="Product Version">
                  <FullProductName ProductID="P-9132V-4.5 SP3a-k">Health Sciences Product Version 4.5 SP3a-k</FullProductName>
               </Branch>
               <Branch Name="4.6 SP0" Type="Product Version">
                  <FullProductName ProductID="P-9132V-4.6 SP0">Health Sciences Product Version 4.6 SP0</FullProductName>
               </Branch>
               <Branch Name="4.6 SP0a-c" Type="Product Version">
                  <FullProductName ProductID="P-9132V-4.6 SP0a-c">Health Sciences Product Version 4.6 SP0a-c</FullProductName>
               </Branch>
               <Branch Name="4.6 SP1" Type="Product Version">
                  <FullProductName ProductID="P-9132V-4.6 SP1">Health Sciences Product Version 4.6 SP1</FullProductName>
               </Branch>
               <Branch Name="4.6 SP1a-c" Type="Product Version">
                  <FullProductName ProductID="P-9132V-4.6 SP1a-c">Health Sciences Product Version 4.6 SP1a-c</FullProductName>
               </Branch>
               <Branch Name="4.6 SP2" Type="Product Version">
                  <FullProductName ProductID="P-9132V-4.6 SP2">Health Sciences Product Version 4.6 SP2</FullProductName>
               </Branch>
               <Branch Name="4.6 SP2a-c" Type="Product Version">
                  <FullProductName ProductID="P-9132V-4.6 SP2a-c">Health Sciences Product Version 4.6 SP2a-c</FullProductName>
               </Branch>
               <Branch Name="5.0 SP0" Type="Product Version">
                  <FullProductName ProductID="P-9132V-5.0 SP0">Health Sciences Product Version 5.0 SP0</FullProductName>
               </Branch>
               <Branch Name="5.0 SP0a" Type="Product Version">
                  <FullProductName ProductID="P-9132V-5.0 SP0a">Health Sciences Product Version 5.0 SP0a</FullProductName>
               </Branch>
               <Branch Name="5.0 SP1" Type="Product Version">
                  <FullProductName ProductID="P-9132V-5.0 SP1">Health Sciences Product Version 5.0 SP1</FullProductName>
               </Branch>
               <Branch Name="5.0 SP1a-b" Type="Product Version">
                  <FullProductName ProductID="P-9132V-5.0 SP1a-b">Health Sciences Product Version 5.0 SP1a-b</FullProductName>
               </Branch>
               <Branch Name="5.0.3" Type="Product Version">
                  <FullProductName ProductID="P-9132V-5.0.3">Health Sciences Product Version 5.0.3</FullProductName>
               </Branch>
               <Branch Name="5.0.4" Type="Product Version">
                  <FullProductName ProductID="P-9132V-5.0.4">Health Sciences Product Version 5.0.4</FullProductName>
               </Branch>
               <Branch Name="5.5 SP0" Type="Product Version">
                  <FullProductName ProductID="P-9132V-5.5 SP0">Health Sciences Product Version 5.5 SP0</FullProductName>
               </Branch>
               <Branch Name="5.5 SP0b" Type="Product Version">
                  <FullProductName ProductID="P-9132V-5.5 SP0b">Health Sciences Product Version 5.5 SP0b</FullProductName>
               </Branch>
               <Branch Name="5.5.1" Type="Product Version">
                  <FullProductName ProductID="P-9132V-5.5.1">Health Sciences Product Version 5.5.1</FullProductName>
               </Branch>
               <Branch Name="6.0.0" Type="Product Version">
                  <FullProductName ProductID="P-9132V-6.0.0">Health Sciences Product Version 6.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel Life Sciences" Type="Product Name">
               <Branch Name="8.1.1.x" Type="Product Version">
                  <FullProductName ProductID="P-9173V-8.1.1.x">Siebel Life Sciences Version 8.1.1.x</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Java SE" Type="Product Family">
            <Branch Name="Java" Type="Product Name">
               <Branch Name="JRockit R27.7.6 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-856V-JRockit R27.7.6 and earlier">Java Version JRockit R27.7.6 and earlier</FullProductName>
               </Branch>
               <Branch Name="JRockit R28.2.8 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-856V-JRockit R28.2.8 and earlier">Java Version JRockit R28.2.8 and earlier</FullProductName>
               </Branch>
               <Branch Name="Java SE 5.0u51 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE 5.0u51 and earlier">Java Version Java SE 5.0u51 and earlier</FullProductName>
               </Branch>
               <Branch Name="Java SE 6u60 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE 6u60 and earlier">Java Version Java SE 6u60 and earlier</FullProductName>
               </Branch>
               <Branch Name="Java SE 7u25 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE 7u25 and earlier">Java Version Java SE 7u25 and earlier</FullProductName>
               </Branch>
               <Branch Name="Java SE 7u40 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE 7u40 and earlier">Java Version Java SE 7u40 and earlier</FullProductName>
               </Branch>
               <Branch Name="Java SE Embedded 7u25 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE Embedded 7u25 and earlier">Java Version Java SE Embedded 7u25 and earlier</FullProductName>
               </Branch>
               <Branch Name="Java SE Embedded 7u40 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE Embedded 7u40 and earlier">Java Version Java SE Embedded 7u40 and earlier</FullProductName>
               </Branch>
               <Branch Name="JavaFX 2.2.40 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-856V-JavaFX 2.2.40 and earlier">Java Version JavaFX 2.2.40 and earlier</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle MySQL" Type="Product Family">
            <Branch Name="MySQL Server" Type="Product Name">
               <Branch Name="5.1" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.1">MySQL Server Version 5.1</FullProductName>
               </Branch>
               <Branch Name="5.1.70 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.1.70 and earlier">MySQL Server Version 5.1.70 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.5.22 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.5.22 and earlier">MySQL Server Version 5.5.22 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.5.32 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.5.32 and earlier">MySQL Server Version 5.5.32 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.6.11 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.6.11 and earlier">MySQL Server Version 5.6.11 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.6.12 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.6.12 and earlier">MySQL Server Version 5.6.12 and earlier</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MySQL Enterprise Monitor" Type="Product Name">
               <Branch Name="2.3.13 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8480V-2.3.13 and earlier">MySQL Enterprise Monitor Version 2.3.13 and earlier</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle PeopleSoft Products" Type="Product Family">
            <Branch Name="PeopleSoft Enterprise HRMS Candidate Gateway" Type="Product Name">
               <Branch Name="9.1" Type="Product Version">
                  <FullProductName ProductID="P-5043V-9.1">PeopleSoft Enterprise HRMS Candidate Gateway Version 9.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise HRMS eCompensation" Type="Product Name">
               <Branch Name="9.1" Type="Product Version">
                  <FullProductName ProductID="P-5046V-9.1">PeopleSoft Enterprise HRMS eCompensation Version 9.1</FullProductName>
               </Branch>
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-5046V-9.2">PeopleSoft Enterprise HRMS eCompensation Version 9.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise PT PeopleTools" Type="Product Name">
               <Branch Name="8.51" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.51">PeopleSoft Enterprise PT PeopleTools Version 8.51</FullProductName>
               </Branch>
               <Branch Name="8.52" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.52">PeopleSoft Enterprise PT PeopleTools Version 8.52</FullProductName>
               </Branch>
               <Branch Name="8.53" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.53">PeopleSoft Enterprise PT PeopleTools Version 8.53</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Primavera Products Suite" Type="Product Family">
            <Branch Name="Primavera P6 Enterprise Project Portfolio Management" Type="Product Name">
               <Branch Name="8.1" Type="Product Version">
                  <FullProductName ProductID="P-5579V-8.1">Primavera P6 Enterprise Project Portfolio Management Version 8.1</FullProductName>
               </Branch>
               <Branch Name="8.2" Type="Product Version">
                  <FullProductName ProductID="P-5579V-8.2">Primavera P6 Enterprise Project Portfolio Management Version 8.2</FullProductName>
               </Branch>
               <Branch Name="8.3" Type="Product Version">
                  <FullProductName ProductID="P-5579V-8.3">Primavera P6 Enterprise Project Portfolio Management Version 8.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Instantis EnterpriseTrack" Type="Product Name">
               <Branch Name="8.0.6" Type="Product Version">
                  <FullProductName ProductID="P-10563V-8.0.6">Instantis EnterpriseTrack Version 8.0.6</FullProductName>
               </Branch>
               <Branch Name="8.5" Type="Product Version">
                  <FullProductName ProductID="P-10563V-8.5">Instantis EnterpriseTrack Version 8.5</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Siebel CRM" Type="Product Family">
            <Branch Name="Siebel Core - Server BizLogic Script" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9001V-8.1.1">Siebel Core - Server BizLogic Script Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9001V-8.2.2">Siebel Core - Server BizLogic Script Version 8.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel Core - Server Infrastructure" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9004V-8.1.1">Siebel Core - Server Infrastructure Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9004V-8.2.2">Siebel Core - Server Infrastructure Version 8.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel UI Framework" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9011V-8.1.1">Siebel UI Framework Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9011V-8.2.2">Siebel UI Framework Version 8.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel Core - EAI" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9021V-8.1.1">Siebel Core - EAI Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9021V-8.2.2">Siebel Core - EAI Version 8.2.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Siebel Server Remote" Type="Product Name">
               <Branch Name="8.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9028V-8.1.1">Siebel Server Remote Version 8.1.1</FullProductName>
               </Branch>
               <Branch Name="8.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9028V-8.2.2">Siebel Server Remote Version 8.2.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Supply Chain Products Suite" Type="Product Family">
            <Branch Name="Transportation Management" Type="Product Name">
               <Branch Name="6.3" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3">Transportation Management Version 6.3</FullProductName>
               </Branch>
               <Branch Name="6.3.1" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.1">Transportation Management Version 6.3.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Agile PLM Framework" Type="Product Name">
               <Branch Name="9.3.2" Type="Product Version">
                  <FullProductName ProductID="P-4461V-9.3.2">Agile PLM Framework Version 9.3.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Virtualization" Type="Product Family">
            <Branch Name="Oracle VM VirtualBox" Type="Product Name">
               <Branch Name="4.0.20" Type="Product Version">
                  <FullProductName ProductID="P-8370V-4.0.20">Oracle VM VirtualBox Version 4.0.20</FullProductName>
               </Branch>
               <Branch Name="4.1.28" Type="Product Version">
                  <FullProductName ProductID="P-8370V-4.1.28">Oracle VM VirtualBox Version 4.1.28</FullProductName>
               </Branch>
               <Branch Name="4.2.18" Type="Product Version">
                  <FullProductName ProductID="P-8370V-4.2.18">Oracle VM VirtualBox Version 4.2.18</FullProductName>
               </Branch>
               <Branch Name="VirtualBox prior to 3.2.18" Type="Product Version">
                  <FullProductName ProductID="P-8370V-VirtualBox prior to 3.2.18">Oracle VM VirtualBox Version VirtualBox prior to 3.2.18</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Secure Global Desktop" Type="Product Name">
               <Branch Name="5" Type="Product Version">
                  <FullProductName ProductID="P-8539V-5">Secure Global Desktop Version 5</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle and Sun Systems Products Suite" Type="Product Family">
            <Branch Name="SPARC - Sun System Firmware" Type="Product Name">
               <Branch Name="Sun System Firmware before 8.3.0.b" Type="Product Version">
                  <FullProductName ProductID="P-9846V-Sun System Firmware before 8.3.0.b">SPARC - Sun System Firmware Version Sun System Firmware before 8.3.0.b</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="SPARC - Sun System Firmware - NPE" Type="Product Name">
               <Branch Name="7.4.6.c" Type="Product Version">
                  <FullProductName ProductID="P-9847V-7.4.6.c">SPARC - Sun System Firmware - NPE Version 7.4.6.c</FullProductName>
               </Branch>
               <Branch Name="8.3.0.b" Type="Product Version">
                  <FullProductName ProductID="P-9847V-8.3.0.b">SPARC - Sun System Firmware - NPE Version 8.3.0.b</FullProductName>
               </Branch>
               <Branch Name="9.0.0.d and 9.0.1.e" Type="Product Version">
                  <FullProductName ProductID="P-9847V-9.0.0.d and 9.0.1.e">SPARC - Sun System Firmware - NPE Version 9.0.0.d and 9.0.1.e</FullProductName>
               </Branch>
               <Branch Name="Sun System Firmware before 6.7.13" Type="Product Version">
                  <FullProductName ProductID="P-9847V-Sun System Firmware before 6.7.13">SPARC - Sun System Firmware - NPE Version Sun System Firmware before 6.7.13</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="OPUS 10G Ethernet Switch Family" Type="Product Name">
               <Branch Name="Oracle Switch ES1-24 1.3 prior to Patch 17050841" Type="Product Version">
                  <FullProductName ProductID="P-9889V-Oracle Switch ES1-24 1.3 prior to Patch 17050841">OPUS 10G Ethernet Switch Family Version Oracle Switch ES1-24 1.3 prior to Patch 17050841</FullProductName>
               </Branch>
               <Branch Name="Sun Blade 6000 10GBE switched NEM 1.2 prior to Patch 13255101" Type="Product Version">
                  <FullProductName ProductID="P-9889V-Sun Blade 6000 10GBE switched NEM 1.2 prior to Patch 13255101">OPUS 10G Ethernet Switch Family Version Sun Blade 6000 10GBE switched NEM 1.2 prior to Patch 13255101</FullProductName>
               </Branch>
               <Branch Name="Sun Network 10GBE Switch 72P 1.2 prior to Patch 13255111" Type="Product Version">
                  <FullProductName ProductID="P-9889V-Sun Network 10GBE Switch 72P 1.2 prior to Patch 13255111">OPUS 10G Ethernet Switch Family Version Sun Network 10GBE Switch 72P 1.2 prior to Patch 13255111</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Solaris Operating System" Type="Product Name">
               <Branch Name="10" Type="Product Version">
                  <FullProductName ProductID="P-10006V-10">Solaris Operating System Version 10</FullProductName>
               </Branch>
               <Branch Name="11.1" Type="Product Version">
                  <FullProductName ProductID="P-10006V-11.1">Solaris Operating System Version 11.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle iLearning" Type="Product Family">
            <Branch Name="iLearning" Type="Product Name">
               <Branch Name="5.2.1" Type="Product Version">
                  <FullProductName ProductID="P-902V-5.2.1">iLearning Version 5.2.1</FullProductName>
               </Branch>
               <Branch Name="6.0" Type="Product Version">
                  <FullProductName ProductID="P-902V-6.0">iLearning Version 6.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
      </Branch>
   </ProductTree>
   <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2011-3389</Title>
      <Notes>
         <Note Audience="All" Ordinal="1" Title="Details" Type="Details">Vulnerability in the Oracle Security Service component of Oracle Fusion Middleware (subcomponent: None).  Supported versions that are affected are FMW: 11.1.1.6 and  11.1.1.7 Forms: 11.1.2.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Security Service accessible data.  CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2011-3389</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-991V-FMW: 11.1.1.6</ProductID>
            <ProductID>P-991V-11.1.1.7 Forms: 11.1.2.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-991V-FMW: 11.1.1.6</ProductID>
            <ProductID>P-991V-11.1.1.7 Forms: 11.1.2.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-2750</Title>
      <Notes>
         <Note Audience="All" Ordinal="2" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Optimizer).  Supported versions that are affected are 5.1 and  5.5.22 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-2750</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1</ProductID>
            <ProductID>P-8478V-5.5.22 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-8478V-5.1</ProductID>
            <ProductID>P-8478V-5.5.22 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-0149</Title>
      <Notes>
         <Note Audience="All" Ordinal="3" Title="Details" Type="Details">Vulnerability in the Sun Blade 6000 10GBE switched NEM, Sun Network 10GBE Switch 72P, Oracle Switch component of Oracle and Sun Systems Products Suite (subcomponent: Switch Platform Software).  Supported versions that are affected are Sun Blade 6000 10GBE switched NEM 1.2 prior to Patch 13255101, Sun Network 10GBE Switch 72P 1.2 prior to Patch 13255111 and  Oracle Switch ES1-24 1.3 prior to Patch 17050841. Difficult to exploit vulnerability allows successful unauthenticated network attacks via OSPF.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Sun Blade 6000 10GBE switched NEM, Sun Network 10GBE Switch 72P, Oracle Switch accessible data and ability to cause a partial denial of service (partial DOS) of Sun Blade 6000 10GBE switched NEM, Sun Network 10GBE Switch 72P, Oracle Switch.  CVSS Base Score 5.8 (Confidentiality and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-0149</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9889V-Sun Blade 6000 10GBE switched NEM 1.2 prior to Patch 13255101</ProductID>
            <ProductID>P-9889V-Sun Network 10GBE Switch 72P 1.2 prior to Patch 13255111</ProductID>
            <ProductID>P-9889V-Oracle Switch ES1-24 1.3 prior to Patch 17050841</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-9889V-Sun Blade 6000 10GBE switched NEM 1.2 prior to Patch 13255101</ProductID>
            <ProductID>P-9889V-Sun Network 10GBE Switch 72P 1.2 prior to Patch 13255111</ProductID>
            <ProductID>P-9889V-Oracle Switch ES1-24 1.3 prior to Patch 17050841</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-0169</Title>
      <Notes>
         <Note Audience="All" Ordinal="4" Title="Details" Type="Details">Vulnerability in the Oracle Security Service component of Oracle Fusion Middleware (subcomponent: None).  Supported versions that are affected are FMW: 11.1.1.6 and  11.1.1.7 Forms: 11.1.2.1 OHS: 12.1.2. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL/TLS.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Security Service accessible data.  CVSS Base Score 2.6 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-0169</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-991V-FMW: 11.1.1.6</ProductID>
            <ProductID>P-991V-11.1.1.7 Forms: 11.1.2.1 OHS: 12.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-991V-FMW: 11.1.1.6</ProductID>
            <ProductID>P-991V-11.1.1.7 Forms: 11.1.2.1 OHS: 12.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-2172</Title>
      <Notes>
         <Note Audience="All" Ordinal="5" Title="Details" Type="Details">Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Metro).  Supported versions that are affected are 2.1.1, 3.0.1 and  3.1.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SOAP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle GlassFish Server accessible data.   Note: CVE-2013-2172 is equivalent to CVE-2013-2461. CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-2172</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8493V-2.1.1</ProductID>
            <ProductID>P-8493V-3.0.1</ProductID>
            <ProductID>P-8493V-3.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-8493V-2.1.1</ProductID>
            <ProductID>P-8493V-3.0.1</ProductID>
            <ProductID>P-8493V-3.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-2251</Title>
      <Notes>
         <Note Audience="All" Ordinal="6" Title="Details" Type="Details">Vulnerability in the MySQL Enterprise Monitor component of Oracle MySQL (subcomponent: Service Manager).  Supported versions that are affected are 2.3.13 and earlier. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: The following CVEs are fixed as a result of upgrading to Struts 2.3.15.1: CVE-2013-2251, CVE-2013-2248, CVE-2013-2135, and CVE-2013-2134. The CVSS score is 8.5 if MySQL Enterprise Monitor runs with admin or root privileges. The score would be 6.0 if MySQL Enterprise Monitor runs with non-admin privileges and the impact on Confidentiality, Integrity and Availability would be Partial. CVSS Base Score 8.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:M/Au:S/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-2251</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8480V-2.3.13 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>8.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-8480V-2.3.13 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-2251</Title>
      <Notes>
         <Note Audience="All" Ordinal="7" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Software (subcomponent: Core).  Supported versions that are affected are 1.7, 2.0, 2.0.1, 2.2.0.1, 3.0 and  12.0.1. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized takeover of Oracle FLEXCUBE Private Banking possibly including arbitrary code execution within the Oracle FLEXCUBE Private Banking.   Note: The following CVEs are fixed as a result of upgrading to Struts 2.3.15.1: CVE-2013-2251, CVE-2013-2248, CVE-2013-2135, and CVE-2013-2134. CVSS Base Score 6.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:P+/I:P+/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-2251</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-1.7</ProductID>
            <ProductID>P-9110V-2.0</ProductID>
            <ProductID>P-9110V-2.0.1</ProductID>
            <ProductID>P-9110V-2.2.0.1</ProductID>
            <ProductID>P-9110V-3.0</ProductID>
            <ProductID>P-9110V-12.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.0</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-9110V-1.7</ProductID>
            <ProductID>P-9110V-2.0</ProductID>
            <ProductID>P-9110V-2.0.1</ProductID>
            <ProductID>P-9110V-2.2.0.1</ProductID>
            <ProductID>P-9110V-3.0</ProductID>
            <ProductID>P-9110V-12.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3762</Title>
      <Notes>
         <Note Audience="All" Ordinal="8" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Schema Management).  Supported versions that are affected are EM Base Platform: 10.2.0.5, 11.1.0.1&lt;br/&gt;
EM DB Control: 11.1.0.7, 11.2.0.2, 11.2.0.3&lt;br/&gt;
EM Plugin for DB: 12.1.0.2, 12.1.0.3 and  12.1.0.4&lt;br/&gt;. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager Base Platform accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3762</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1366V-EM Base Platform: 10.2.0.5</ProductID>
            <ProductID>P-1366V-11.1.0.1EM DB Control: 11.1.0.7</ProductID>
            <ProductID>P-1366V-11.2.0.2</ProductID>
            <ProductID>P-1366V-11.2.0.3EM Plugin for DB: 12.1.0.2</ProductID>
            <ProductID>P-1366V-12.1.0.3</ProductID>
            <ProductID>P-1366V-12.1.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-1366V-EM Base Platform: 10.2.0.5</ProductID>
            <ProductID>P-1366V-11.1.0.1EM DB Control: 11.1.0.7</ProductID>
            <ProductID>P-1366V-11.2.0.2</ProductID>
            <ProductID>P-1366V-11.2.0.3EM Plugin for DB: 12.1.0.2</ProductID>
            <ProductID>P-1366V-12.1.0.3</ProductID>
            <ProductID>P-1366V-12.1.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3766</Title>
      <Notes>
         <Note Audience="All" Ordinal="9" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access).  Supported versions that are affected are 8.1, 8.2 and  8.3. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Primavera P6 Enterprise Project Portfolio Management accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3766</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-8.1</ProductID>
            <ProductID>P-5579V-8.2</ProductID>
            <ProductID>P-5579V-8.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-5579V-8.1</ProductID>
            <ProductID>P-5579V-8.2</ProductID>
            <ProductID>P-5579V-8.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3785</Title>
      <Notes>
         <Note Audience="All" Ordinal="10" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise HRMS component of Oracle PeopleSoft Products (subcomponent: Career's Home).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise HRMS accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3785</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5043V-9.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-5043V-9.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3792</Title>
      <Notes>
         <Note Audience="All" Ordinal="11" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).  Supported versions that are affected are VirtualBox prior to 3.2.18, 4.0.20, 4.1.28 and  4.2.18. Very difficult to exploit vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 3.8 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:H/Au:S/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:H/Au:S/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3792</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-VirtualBox prior to 3.2.18</ProductID>
            <ProductID>P-8370V-4.0.20</ProductID>
            <ProductID>P-8370V-4.1.28</ProductID>
            <ProductID>P-8370V-4.2.18</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.8</BaseScore>
            <Vector>AV:L/AC:H/Au:S/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-8370V-VirtualBox prior to 3.2.18</ProductID>
            <ProductID>P-8370V-4.0.20</ProductID>
            <ProductID>P-8370V-4.1.28</ProductID>
            <ProductID>P-8370V-4.2.18</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3814</Title>
      <Notes>
         <Note Audience="All" Ordinal="12" Title="Details" Type="Details">Vulnerability in the Oracle Retail Invoice Matching component of Oracle Industry Applications (subcomponent: System Administration).  Supported versions that are affected are 10.2, 11.0, 12.0, 12.0IN, 12.1, 13.0, 13.1 and  13.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Retail Invoice Matching accessible data as well as  read access to all Oracle Retail Invoice Matching accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3814</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1810V-10.2</ProductID>
            <ProductID>P-1810V-11.0</ProductID>
            <ProductID>P-1810V-12.0</ProductID>
            <ProductID>P-1810V-12.0IN</ProductID>
            <ProductID>P-1810V-12.1</ProductID>
            <ProductID>P-1810V-13.0</ProductID>
            <ProductID>P-1810V-13.1</ProductID>
            <ProductID>P-1810V-13.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-1810V-10.2</ProductID>
            <ProductID>P-1810V-11.0</ProductID>
            <ProductID>P-1810V-12.0</ProductID>
            <ProductID>P-1810V-12.0IN</ProductID>
            <ProductID>P-1810V-12.1</ProductID>
            <ProductID>P-1810V-13.0</ProductID>
            <ProductID>P-1810V-13.1</ProductID>
            <ProductID>P-1810V-13.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3826</Title>
      <Notes>
         <Note Audience="All" Ordinal="13" Title="Details" Type="Details">Vulnerability in the Core RDBMS component of Oracle Database Server.  Supported versions that are affected are 11.1.0.7, 11.2.0.2, 11.2.0.3 and  12.1.0.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Core RDBMS accessible data.   Note: Network encryption (native network encryption and SSL/TLS) and strong authentication services (Kerberos, PKI, and RADIUS) are no longer part of Oracle Advanced Security and are available in all licensed editions of all supported releases of the Oracle database. To remediate this security vulnerability, customers should configure network encryption in their clients and servers to protect sensitive data sent over untrusted networks. Refer to &lt;A HREF="http://docs.oracle.com/cd/E11882_01/license.112/e47877/options.htm#CIHFDJDG"&gt;http://docs.oracle.com/cd/E11882_01/license.112/e47877/options.htm#CIHFDJDG&lt;/A&gt;
- "Oracle Advanced Security section" of "Oracle Database Licensing Information 11&lt;i&gt;g&lt;/i&gt; Release 2 (11.2)" for details of this licensing change. CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3826</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.2</ProductID>
            <ProductID>P-5V-11.2.0.3</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-5V-11.1.0.7</ProductID>
            <ProductID>P-5V-11.2.0.2</ProductID>
            <ProductID>P-5V-11.2.0.3</ProductID>
            <ProductID>P-5V-12.1.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3827</Title>
      <Notes>
         <Note Audience="All" Ordinal="14" Title="Details" Type="Details">Vulnerability in the Oracle JDeveloper component of Oracle Fusion Middleware (subcomponent: Java Server Faces).  Supported versions that are affected are 11.1.2.3.0, 11.1.2.4.0 and  12.1.2.0.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle JDeveloper accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3827</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-807V-11.1.2.3.0</ProductID>
            <ProductID>P-807V-11.1.2.4.0</ProductID>
            <ProductID>P-807V-12.1.2.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-807V-11.1.2.3.0</ProductID>
            <ProductID>P-807V-11.1.2.4.0</ProductID>
            <ProductID>P-807V-12.1.2.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3827</Title>
      <Notes>
         <Note Audience="All" Ordinal="15" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Container).  Supported versions that are affected are 10.3.6.0 and  12.1.1.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle WebLogic Server accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3827</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3827</Title>
      <Notes>
         <Note Audience="All" Ordinal="16" Title="Details" Type="Details">Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Java Server Faces).  Supported versions that are affected are 2.1.1, 3.0.1 and  3.1.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle GlassFish Server accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3827</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8493V-2.1.1</ProductID>
            <ProductID>P-8493V-3.0.1</ProductID>
            <ProductID>P-8493V-3.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-8493V-2.1.1</ProductID>
            <ProductID>P-8493V-3.0.1</ProductID>
            <ProductID>P-8493V-3.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="17" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3828</Title>
      <Notes>
         <Note Audience="All" Ordinal="17" Title="Details" Type="Details">Vulnerability in the Oracle Web Services component of Oracle Fusion Middleware (subcomponent: Test Page).  Supported versions that are affected are 10.1.3.5.0 and  11.1.1.6.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Oracle Web Services accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3828</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1271V-10.1.3.5.0</ProductID>
            <ProductID>P-1271V-11.1.1.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-1271V-10.1.3.5.0</ProductID>
            <ProductID>P-1271V-11.1.1.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="18" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3829</Title>
      <Notes>
         <Note Audience="All" Ordinal="18" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE, Java SE Embedded accessible data as well as  read access to a subset of Java SE, Java SE Embedded accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3829</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="19" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3831</Title>
      <Notes>
         <Note Audience="All" Ordinal="19" Title="Details" Type="Details">Vulnerability in the Oracle Portal component of Oracle Fusion Middleware (subcomponent: Demos).   The supported version that is affected is 11.1.1.6.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Portal accessible data as well as  read access to all Oracle Portal accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3831</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-96V-11.1.1.6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-96V-11.1.1.6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="20" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3832</Title>
      <Notes>
         <Note Audience="All" Ordinal="20" Title="Details" Type="Details">Vulnerability in the Siebel Server Remote component of Oracle Siebel CRM (subcomponent: File System Management).  Supported versions that are affected are 8.1.1 and  8.2.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Siebel Server Remote accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3832</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9028V-8.1.1</ProductID>
            <ProductID>P-9028V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-9028V-8.1.1</ProductID>
            <ProductID>P-9028V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="21" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3833</Title>
      <Notes>
         <Note Audience="All" Ordinal="21" Title="Details" Type="Details">Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Authentication Engine).  Supported versions that are affected are 11.1.1.5.0 and  11.1.2.0.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Access Manager accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3833</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5565V-11.1.1.5.0</ProductID>
            <ProductID>P-5565V-11.1.2.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-5565V-11.1.1.5.0</ProductID>
            <ProductID>P-5565V-11.1.2.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="22" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3834</Title>
      <Notes>
         <Note Audience="All" Ordinal="22" Title="Details" Type="Details">Vulnerability in the Oracle Secure Global Desktop component of Oracle Virtualization (subcomponent: ttaauxserv).   The supported version that is affected is 5. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Secure Global Desktop.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3834</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8539V-5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-8539V-5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="23" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3835</Title>
      <Notes>
         <Note Audience="All" Ordinal="23" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker).  Supported versions that are affected are 8.51, 8.52 and  8.53. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3835</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
            <ProductID>P-5085V-8.53</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
            <ProductID>P-5085V-8.53</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="24" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3836</Title>
      <Notes>
         <Note Audience="All" Ordinal="24" Title="Details" Type="Details">Vulnerability in the Oracle Web Cache component of Oracle Fusion Middleware (subcomponent: ESI/Partial Page Caching).  Supported versions that are affected are 11.1.1.6 and  11.1.1.7. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to all Oracle Web Cache accessible data.  CVSS Base Score 3.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P+/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3836</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1059V-11.1.1.6</ProductID>
            <ProductID>P-1059V-11.1.1.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-1059V-11.1.1.6</ProductID>
            <ProductID>P-1059V-11.1.1.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="25" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3837</Title>
      <Notes>
         <Note Audience="All" Ordinal="25" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle and Sun Systems Products Suite (subcomponent: Cacao).  Supported versions that are affected are 10 and  11.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SNMP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 4.3 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3837</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="26" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3838</Title>
      <Notes>
         <Note Audience="All" Ordinal="26" Title="Details" Type="Details">Vulnerability in the SPARC Enterprise T &amp; M Series Servers  component of Oracle and Sun Systems Products Suite (subcomponent: Sun System Firmware/Hypervisor).  Supported versions that are affected are Sun System Firmware before 6.7.13, 7.4.6.c, 8.3.0.b and  9.0.0.d and 9.0.1.e. Very difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).   Note: CVE-2013-3838 applies to Sun System Firmware before 6.7.13 for SPARC T1, 7.4.6.c for SPARC T2, 8.3.0.b for SPARC T3 &amp; T4, 9.0.0.d for SPARC T5 and 9.0.1.e for SPARC M5. CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:H/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:H/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3838</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9847V-Sun System Firmware before 6.7.13</ProductID>
            <ProductID>P-9847V-7.4.6.c</ProductID>
            <ProductID>P-9847V-8.3.0.b</ProductID>
            <ProductID>P-9847V-9.0.0.d and 9.0.1.e</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:L/AC:H/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-9847V-Sun System Firmware before 6.7.13</ProductID>
            <ProductID>P-9847V-7.4.6.c</ProductID>
            <ProductID>P-9847V-8.3.0.b</ProductID>
            <ProductID>P-9847V-9.0.0.d and 9.0.1.e</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="27" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3839</Title>
      <Notes>
         <Note Audience="All" Ordinal="27" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Optimizer).  Supported versions that are affected are 5.1.70 and earlier, 5.5.32 and earlier and  5.6.12 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3839</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.1.70 and earlier</ProductID>
            <ProductID>P-8478V-5.5.32 and earlier</ProductID>
            <ProductID>P-8478V-5.6.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-8478V-5.1.70 and earlier</ProductID>
            <ProductID>P-8478V-5.5.32 and earlier</ProductID>
            <ProductID>P-8478V-5.6.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="28" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3840</Title>
      <Notes>
         <Note Audience="All" Ordinal="28" Title="Details" Type="Details">Vulnerability in the Siebel Core - EAI component of Oracle Siebel CRM (subcomponent: Web Services).  Supported versions that are affected are 8.1.1 and  8.2.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Siebel Core - EAI accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3840</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9021V-8.1.1</ProductID>
            <ProductID>P-9021V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-9021V-8.1.1</ProductID>
            <ProductID>P-9021V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="29" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3841</Title>
      <Notes>
         <Note Audience="All" Ordinal="29" Title="Details" Type="Details">Vulnerability in the Siebel Core - EAI component of Oracle Siebel CRM (subcomponent: Web Services).  Supported versions that are affected are 8.1.1 and  8.2.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Siebel Core - EAI accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3841</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9021V-8.1.1</ProductID>
            <ProductID>P-9021V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-9021V-8.1.1</ProductID>
            <ProductID>P-9021V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="30" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-3842</Title>
      <Notes>
         <Note Audience="All" Ordinal="30" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle and Sun Systems Products Suite (subcomponent: Oracle Configuration Manager (OCM)).   The supported version that is affected is 10. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Solaris accessible data.  CVSS Base Score 2.1 (Confidentiality impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-3842</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-10006V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="31" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-4002</Title>
      <Notes>
         <Note Audience="All" Ordinal="31" Title="Details" Type="Details">Vulnerability in the Java SE, JRockit, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, JRockit, Java SE Embedded.   Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-4002</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="32" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5761</Title>
      <Notes>
         <Note Audience="All" Ordinal="32" Title="Details" Type="Details">Vulnerability in the Siebel Core - Server BizLogic Script component of Oracle Siebel CRM (subcomponent: Integration - Scripting).  Supported versions that are affected are 8.1.1 and  8.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Siebel Core - Server BizLogic Script accessible data as well as  read access to a subset of Siebel Core - Server BizLogic Script accessible data.  CVSS Base Score 5.8 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5761</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-9001V-8.1.1</ProductID>
            <ProductID>P-9001V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="33" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5762</Title>
      <Notes>
         <Note Audience="All" Ordinal="33" Title="Details" Type="Details">Vulnerability in the Oracle Siebel CTMS component of Oracle Industry Applications (subcomponent: SC-OC Integration).   The supported version that is affected is 8.1.1.x. Very difficult to exploit vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Siebel CTMS and  read access to a subset of Oracle Siebel CTMS accessible data.  CVSS Base Score 2.4 (Confidentiality and Availability impacts).  CVSS V2 Vector: (AV:L/AC:H/Au:S/C:P/I:N/A:P).  Oracle Vector: (AV:L/AC:H/Au:S/C:P/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5762</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9173V-8.1.1.x</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.4</BaseScore>
            <Vector>AV:L/AC:H/Au:S/C:P/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-9173V-8.1.1.x</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="34" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5763</Title>
      <Notes>
         <Note Audience="All" Ordinal="34" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Maintenance).   The supported version that is affected is 8.4.0. Difficult to exploit vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS Base Score would increase to 6.8. CVSS Base Score 1.5 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:M/Au:S/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5763</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.5</BaseScore>
            <Vector>AV:L/AC:M/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-2276V-8.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="35" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5765</Title>
      <Notes>
         <Note Audience="All" Ordinal="35" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: XML Publisher).  Supported versions that are affected are 8.51, 8.52 and  8.53. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5765</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
            <ProductID>P-5085V-8.53</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
            <ProductID>P-5085V-8.53</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="36" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5766</Title>
      <Notes>
         <Note Audience="All" Ordinal="36" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: DB Performance Advisories/UIs).  Supported versions that are affected are EM Base Platform: 10.2.0.5, 11.1.0.1 &lt;br/&gt;
EM DB Control: 11.1.0.7, 11.2.0.2, 11.2.0.3 &lt;br/&gt;
EM Plugin for DB: 12.1.0.2 and  12.1.0.3. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Enterprise Manager Base Platform accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5766</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1366V-EM Base Platform: 10.2.0.5</ProductID>
            <ProductID>P-1366V-11.1.0.1 EM DB Control: 11.1.0.7</ProductID>
            <ProductID>P-1366V-11.2.0.2</ProductID>
            <ProductID>P-1366V-11.2.0.3 EM Plugin for DB: 12.1.0.2</ProductID>
            <ProductID>P-1366V-12.1.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-1366V-EM Base Platform: 10.2.0.5</ProductID>
            <ProductID>P-1366V-11.1.0.1 EM DB Control: 11.1.0.7</ProductID>
            <ProductID>P-1366V-11.2.0.2</ProductID>
            <ProductID>P-1366V-11.2.0.3 EM Plugin for DB: 12.1.0.2</ProductID>
            <ProductID>P-1366V-12.1.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="37" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5767</Title>
      <Notes>
         <Note Audience="All" Ordinal="37" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Optimizer).  Supported versions that are affected are 5.6.12 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5767</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-8478V-5.6.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="38" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5768</Title>
      <Notes>
         <Note Audience="All" Ordinal="38" Title="Details" Type="Details">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: ActiveX Controls).  Supported versions that are affected are 8.1.1 and  8.2.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Siebel UI Framework accessible data.  CVSS Base Score 4.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5768</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="39" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5769</Title>
      <Notes>
         <Note Audience="All" Ordinal="39" Title="Details" Type="Details">Vulnerability in the Siebel Core - EAI component of Oracle Siebel CRM (subcomponent: Web Services).   The supported version that is affected is 8.1.1. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel Core - EAI.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5769</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9021V-8.1.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-9021V-8.1.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="40" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5770</Title>
      <Notes>
         <Note Audience="All" Ordinal="40" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Locking).  Supported versions that are affected are 5.6.11 and earlier. Very difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 2.1 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:H/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5770</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.11 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-8478V-5.6.11 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="41" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5771</Title>
      <Notes>
         <Note Audience="All" Ordinal="41" Title="Details" Type="Details">Vulnerability in the XML Parser component of Oracle Database Server. For supported versions that are affected see note. Easily exploitable vulnerability allows successful unauthenticated network attacks via Oracle Net.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of XML Parser accessible data and ability to cause a partial denial of service (partial DOS) of XML Parser.   Note: Fixed in all supported releases and patchsets. CVSS Base Score 6.4 (Confidentiality and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5771</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V--</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-5V--</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="42" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5772</Title>
      <Notes>
         <Note Audience="All" Ordinal="42" Title="Details" Type="Details">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: jhat).  Supported versions that are affected are Java SE 7u40 and earlier and  Java SE 6u60 and earlier. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE accessible data.   Note: Applies to the jhat developer tool. CVSS Base Score 2.6 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:H/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5772</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="43" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5773</Title>
      <Notes>
         <Note Audience="All" Ordinal="43" Title="Details" Type="Details">Vulnerability in the Oracle Containers for J2EE component of Oracle Fusion Middleware (subcomponent: Servlet Runtime).   The supported version that is affected is 10.1.3.5.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Containers for J2EE accessible data.   Note: Please refer to MOS note &lt;A HREF="https://support.oracle.com/epmos/faces/DocumentDisplay?id=1586861.1"&gt;https://support.oracle.com/epmos/faces/DocumentDisplay?id=1586861.1&lt;/A&gt; for configuration. CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5773</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1270V-10.1.3.5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-1270V-10.1.3.5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="44" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5774</Title>
      <Notes>
         <Note Audience="All" Ordinal="44" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE, Java SE Embedded accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5774</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="45" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5775</Title>
      <Notes>
         <Note Audience="All" Ordinal="45" Title="Details" Type="Details">Vulnerability in the Java SE, JavaFX component of Oracle Java SE (subcomponent: JavaFX).  Supported versions that are affected are Java SE 7u40 and earlier and  JavaFX 2.2.40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE, JavaFX accessible data as well as  read access to a subset of Java SE, JavaFX accessible data and ability to cause a partial denial of service (partial DOS) of Java SE, JavaFX.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5775</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-JavaFX 2.2.40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-JavaFX 2.2.40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="46" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5776</Title>
      <Notes>
         <Note Audience="All" Ordinal="46" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE, Java SE Embedded accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5776</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="47" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5777</Title>
      <Notes>
         <Note Audience="All" Ordinal="47" Title="Details" Type="Details">Vulnerability in the Java SE, JavaFX component of Oracle Java SE (subcomponent: JavaFX).  Supported versions that are affected are Java SE 7u40 and earlier and  JavaFX 2.2.40 and earlier. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 9.3 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5777</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-JavaFX 2.2.40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>9.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-JavaFX 2.2.40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="48" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5778</Title>
      <Notes>
         <Note Audience="All" Ordinal="48" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: 2D).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java SE, Java SE Embedded accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5778</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="49" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5779</Title>
      <Notes>
         <Note Audience="All" Ordinal="49" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: PIA Core Technology).  Supported versions that are affected are 8.51, 8.52 and  8.53. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5779</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
            <ProductID>P-5085V-8.53</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
            <ProductID>P-5085V-8.53</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="50" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5780</Title>
      <Notes>
         <Note Audience="All" Ordinal="50" Title="Details" Type="Details">Vulnerability in the Java SE, JRockit, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier and  Java SE Embedded 7u40 and earlier. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java SE, JRockit, Java SE Embedded accessible data.   Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5780</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="51" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5781</Title>
      <Notes>
         <Note Audience="All" Ordinal="51" Title="Details" Type="Details">Vulnerability in the SPARC Enterprise T4 Servers  component of Oracle and Sun Systems Products Suite (subcomponent: Sun System Firmware/Integrated Lights Out Manager (ILOM)).   The supported version that is affected is Sun System Firmware before 8.3.0.b. Difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 6.9 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:M/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5781</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9846V-Sun System Firmware before 8.3.0.b</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.9</BaseScore>
            <Vector>AV:L/AC:M/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-9846V-Sun System Firmware before 8.3.0.b</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="52" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5782</Title>
      <Notes>
         <Note Audience="All" Ordinal="52" Title="Details" Type="Details">Vulnerability in the Java SE, JRockit, Java SE Embedded component of Oracle Java SE (subcomponent: 2D).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit  R27.7.6 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5782</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="53" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5783</Title>
      <Notes>
         <Note Audience="All" Ordinal="53" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Swing).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE, Java SE Embedded accessible data as well as  read access to a subset of Java SE, Java SE Embedded accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5783</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="54" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5784</Title>
      <Notes>
         <Note Audience="All" Ordinal="54" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: SCRIPTING).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier and  Java SE Embedded 7u40 and earlier. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE, Java SE Embedded accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5784</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="55" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5786</Title>
      <Notes>
         <Note Audience="All" Ordinal="55" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB).  Supported versions that are affected are 5.6.12 and earlier. Easily exploitable vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 4.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5786</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-8478V-5.6.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="56" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5787</Title>
      <Notes>
         <Note Audience="All" Ordinal="56" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5787</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="57" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5788</Title>
      <Notes>
         <Note Audience="All" Ordinal="57" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are Java SE 7u40 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5788</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="58" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5789</Title>
      <Notes>
         <Note Audience="All" Ordinal="58" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5789</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="59" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5790</Title>
      <Notes>
         <Note Audience="All" Ordinal="59" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: BEANS).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier and  Java SE Embedded 7u40 and earlier. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java SE, Java SE Embedded accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5790</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="60" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5791</Title>
      <Notes>
         <Note Audience="All" Ordinal="60" Title="Details" Type="Details">Vulnerability in the Oracle Outside In Technology component of Oracle Fusion Middleware (subcomponent: Outside In Filters).  Supported versions that are affected are 8.4.0 and  8.4.1. Difficult to exploit vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Outside In Technology.   Note: Outside In Technology is a suite of software development kits (SDKs). It does not have any particular associated protocol. If the hosting software passes data received over the network to Outside In Technology code, the CVSS Base Score would increase to 6.8. CVSS Base Score 1.5 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:M/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:M/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5791</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2276V-8.4.0</ProductID>
            <ProductID>P-2276V-8.4.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.5</BaseScore>
            <Vector>AV:L/AC:M/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-2276V-8.4.0</ProductID>
            <ProductID>P-2276V-8.4.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="61" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5792</Title>
      <Notes>
         <Note Audience="All" Ordinal="61" Title="Details" Type="Details">Vulnerability in the Techstack component of Oracle E-Business Suite (subcomponent: Apache).   The supported version that is affected is 12.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Techstack accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5792</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1745V-12.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-1745V-12.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="62" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5793</Title>
      <Notes>
         <Note Audience="All" Ordinal="62" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB).  Supported versions that are affected are 5.6.12 and earlier. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.  CVSS Base Score 3.5 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:N/A:P+).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5793</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-8478V-5.6.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="63" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5794</Title>
      <Notes>
         <Note Audience="All" Ordinal="63" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Portal).  Supported versions that are affected are 8.51, 8.52 and  8.53. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5794</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
            <ProductID>P-5085V-8.53</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
            <ProductID>P-5085V-8.53</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="64" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5796</Title>
      <Notes>
         <Note Audience="All" Ordinal="64" Title="Details" Type="Details">Vulnerability in the Siebel Core - EAI component of Oracle Siebel CRM (subcomponent: Web Services).  Supported versions that are affected are 8.1.1 and  8.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel Core - EAI.  CVSS Base Score 4.3 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5796</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9021V-8.1.1</ProductID>
            <ProductID>P-9021V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-9021V-8.1.1</ProductID>
            <ProductID>P-9021V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="65" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5797</Title>
      <Notes>
         <Note Audience="All" Ordinal="65" Title="Details" Type="Details">Vulnerability in the Java SE, JRockit, JavaFX component of Oracle Java SE (subcomponent: Javadoc).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier and  JavaFX 2.2.40 and earlier. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE, JRockit, JavaFX accessible data.   Note: Applies to sites that run the Javadoc tool as a service and then host the resulting documentation. It is recommended that sites filter HTML where it is not     explicitly allowed for javadocs. CVSS Base Score 3.5 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5797</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
            <ProductID>P-856V-JavaFX 2.2.40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
            <ProductID>P-856V-JavaFX 2.2.40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="66" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5798</Title>
      <Notes>
         <Note Audience="All" Ordinal="66" Title="Details" Type="Details">Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: End User Self Service).  Supported versions that are affected are 11.1.2.0.0 and  11.1.2.1.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Identity Manager accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5798</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1980V-11.1.2.0.0</ProductID>
            <ProductID>P-1980V-11.1.2.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-1980V-11.1.2.0.0</ProductID>
            <ProductID>P-1980V-11.1.2.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="67" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5799</Title>
      <Notes>
         <Note Audience="All" Ordinal="67" Title="Details" Type="Details">Vulnerability in the Oracle Agile PLM Framework component of Oracle Supply Chain Products Suite (subcomponent: Security).   The supported version that is affected is 9.3.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Agile PLM Framework accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5799</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4461V-9.3.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-4461V-9.3.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="68" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5800</Title>
      <Notes>
         <Note Audience="All" Ordinal="68" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS).  Supported versions that are affected are Java SE 7u40 and earlier and  Java SE Embedded 7u40 and earlier. Difficult to exploit vulnerability allows successful unauthenticated network attacks via Kerberos.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java SE, Java SE Embedded accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5800</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="69" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5801</Title>
      <Notes>
         <Note Audience="All" Ordinal="69" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: 2D).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java SE, Java SE Embedded accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5801</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="70" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5802</Title>
      <Notes>
         <Note Audience="All" Ordinal="70" Title="Details" Type="Details">Vulnerability in the Java SE, JRockit, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE, JRockit, Java SE Embedded accessible data as well as  read access to a subset of Java SE, JRockit, Java SE Embedded accessible data and ability to cause a partial denial of service (partial DOS) of Java SE, JRockit, Java SE Embedded.   Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5802</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="71" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5803</Title>
      <Notes>
         <Note Audience="All" Ordinal="71" Title="Details" Type="Details">Vulnerability in the Java SE, JRockit, Java SE Embedded component of Oracle Java SE (subcomponent: JGSS).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier,  JRockit R27.7.6 and earlier and  Java SE Embedded 7u40 and earlier. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via Kerberos.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, JRockit, Java SE Embedded.   Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS Base Score 2.6 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:H/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5803</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="72" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5804</Title>
      <Notes>
         <Note Audience="All" Ordinal="72" Title="Details" Type="Details">Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: Javadoc).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier and  JRockit R27.7.6 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE, JRockit accessible data as well as  read access to a subset of Java SE, JRockit accessible data.   Note: Applies to sites that run the Javadoc tool as a service and then host the resulting documentation. It is recommended that sites filter HTML where it is not     explicitly allowed for javadocs. CVSS Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5804</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="73" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5805</Title>
      <Notes>
         <Note Audience="All" Ordinal="73" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Swing).  Supported versions that are affected are Java SE 7u40 and earlier and  Java SE Embedded 7u40 and earlier. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 9.3 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5805</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>9.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="74" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5806</Title>
      <Notes>
         <Note Audience="All" Ordinal="74" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Swing).  Supported versions that are affected are Java SE 7u40 and earlier and  Java SE Embedded 7u40 and earlier. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 9.3 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5806</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>9.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="75" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5807</Title>
      <Notes>
         <Note Audience="All" Ordinal="75" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Replication).  Supported versions that are affected are 5.5.32 and earlier and  5.6.12 and earlier. Difficult to exploit vulnerability allows successful authenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all MySQL Server accessible data as well as  read access to all MySQL Server accessible data.  CVSS Base Score 4.9 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5807</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.32 and earlier</ProductID>
            <ProductID>P-8478V-5.6.12 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-8478V-5.5.32 and earlier</ProductID>
            <ProductID>P-8478V-5.6.12 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="76" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5809</Title>
      <Notes>
         <Note Audience="All" Ordinal="76" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: 2D).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5809</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="77" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5810</Title>
      <Notes>
         <Note Audience="All" Ordinal="77" Title="Details" Type="Details">Vulnerability in the Java SE, JavaFX component of Oracle Java SE (subcomponent: JavaFX).  Supported versions that are affected are Java SE 7u40 and earlier and  JavaFX 2.2.40 and earlier. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 9.3 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5810</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-JavaFX 2.2.40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>9.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-JavaFX 2.2.40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="78" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5811</Title>
      <Notes>
         <Note Audience="All" Ordinal="78" Title="Details" Type="Details">Vulnerability in the Oracle Health Sciences InForm component of Oracle Industry Applications (subcomponent: Web).  Supported versions that are affected are 4.5 SP3, 4.5 SP3a-k, 4.6 SP0, 4.6 SP0a-c, 4.6 SP1, 4.6 SP1a-c, 4.6 SP2, 4.6 SP2a-c, 5.0 SP0, 5.0 SP0a, 5.0 SP1 and  5.0 SP1a-b. Difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to all Oracle Health Sciences InForm accessible data.  CVSS Base Score 3.5 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:S/C:P+/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5811</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9132V-4.5 SP3</ProductID>
            <ProductID>P-9132V-4.5 SP3a-k</ProductID>
            <ProductID>P-9132V-4.6 SP0</ProductID>
            <ProductID>P-9132V-4.6 SP0a-c</ProductID>
            <ProductID>P-9132V-4.6 SP1</ProductID>
            <ProductID>P-9132V-4.6 SP1a-c</ProductID>
            <ProductID>P-9132V-4.6 SP2</ProductID>
            <ProductID>P-9132V-4.6 SP2a-c</ProductID>
            <ProductID>P-9132V-5.0 SP0</ProductID>
            <ProductID>P-9132V-5.0 SP0a</ProductID>
            <ProductID>P-9132V-5.0 SP1</ProductID>
            <ProductID>P-9132V-5.0 SP1a-b</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.5</BaseScore>
            <Vector>AV:N/AC:M/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-9132V-4.5 SP3</ProductID>
            <ProductID>P-9132V-4.5 SP3a-k</ProductID>
            <ProductID>P-9132V-4.6 SP0</ProductID>
            <ProductID>P-9132V-4.6 SP0a-c</ProductID>
            <ProductID>P-9132V-4.6 SP1</ProductID>
            <ProductID>P-9132V-4.6 SP1a-c</ProductID>
            <ProductID>P-9132V-4.6 SP2</ProductID>
            <ProductID>P-9132V-4.6 SP2a-c</ProductID>
            <ProductID>P-9132V-5.0 SP0</ProductID>
            <ProductID>P-9132V-5.0 SP0a</ProductID>
            <ProductID>P-9132V-5.0 SP1</ProductID>
            <ProductID>P-9132V-5.0 SP1a-b</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="79" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5812</Title>
      <Notes>
         <Note Audience="All" Ordinal="79" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java SE, Java SE Embedded accessible data and ability to cause a partial denial of service (partial DOS) of Java SE, Java SE Embedded.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 6.4 (Confidentiality and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5812</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.4</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="80" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5813</Title>
      <Notes>
         <Note Audience="All" Ordinal="80" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware (subcomponent: Content Server).  Supported versions that are affected are 10.1.3.5.1, 11.1.1.6.0, 11.1.1.7.0 and  11.1.1.8.0. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle WebCenter Content accessible data as well as  read access to all Oracle WebCenter Content accessible data.  CVSS Base Score 5.5 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P+/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5813</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2271V-10.1.3.5.1</ProductID>
            <ProductID>P-2271V-11.1.1.6.0</ProductID>
            <ProductID>P-2271V-11.1.1.7.0</ProductID>
            <ProductID>P-2271V-11.1.1.8.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.5</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-2271V-10.1.3.5.1</ProductID>
            <ProductID>P-2271V-11.1.1.6.0</ProductID>
            <ProductID>P-2271V-11.1.1.7.0</ProductID>
            <ProductID>P-2271V-11.1.1.8.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="81" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5814</Title>
      <Notes>
         <Note Audience="All" Ordinal="81" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: CORBA).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5814</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="82" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5815</Title>
      <Notes>
         <Note Audience="All" Ordinal="82" Title="Details" Type="Details">Vulnerability in the Oracle Identity Analytics component of Oracle Fusion Middleware (subcomponent: Security).  Supported versions that are affected are Oracle Identity Analytics 11.1.1.5, Sun Role Manager 4.1 and  5.0. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Oracle Identity Analytics accessible data as well as  read access to a subset of Oracle Identity Analytics accessible data and ability to cause a partial denial of service (partial DOS) of Oracle Identity Analytics.  CVSS Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:P+/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5815</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8522V-Oracle Identity Analytics 11.1.1.5</ProductID>
            <ProductID>P-8522V-Sun Role Manager 4.1</ProductID>
            <ProductID>P-8522V-5.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.5</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-8522V-Oracle Identity Analytics 11.1.1.5</ProductID>
            <ProductID>P-8522V-Sun Role Manager 4.1</ProductID>
            <ProductID>P-8522V-5.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="83" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5816</Title>
      <Notes>
         <Note Audience="All" Ordinal="83" Title="Details" Type="Details">Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Metro).  Supported versions that are affected are 2.1.1, 3.0.1 and  3.1.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via SOAP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle GlassFish Server.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5816</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8493V-2.1.1</ProductID>
            <ProductID>P-8493V-3.0.1</ProductID>
            <ProductID>P-8493V-3.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-8493V-2.1.1</ProductID>
            <ProductID>P-8493V-3.0.1</ProductID>
            <ProductID>P-8493V-3.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="84" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5817</Title>
      <Notes>
         <Note Audience="All" Ordinal="84" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JNDI).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5817</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="85" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5818</Title>
      <Notes>
         <Note Audience="All" Ordinal="85" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE, Java SE Embedded accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5818</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="86" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5819</Title>
      <Notes>
         <Note Audience="All" Ordinal="86" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE, Java SE Embedded accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5819</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="87" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5820</Title>
      <Notes>
         <Note Audience="All" Ordinal="87" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAX-WS).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE, Java SE Embedded accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5820</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="88" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5822</Title>
      <Notes>
         <Note Audience="All" Ordinal="88" Title="Details" Type="Details">Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Administration).  Supported versions that are affected are 5.2.1 and  6.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle iLearning accessible data as well as  read access to a subset of Oracle iLearning accessible data and ability to cause a partial denial of service (partial DOS) of Oracle iLearning.  CVSS Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5822</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-902V-5.2.1</ProductID>
            <ProductID>P-902V-6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-902V-5.2.1</ProductID>
            <ProductID>P-902V-6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="89" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5823</Title>
      <Notes>
         <Note Audience="All" Ordinal="89" Title="Details" Type="Details">Vulnerability in the Java SE, JRockit, Java SE Embedded component of Oracle Java SE (subcomponent: Security).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, JRockit, Java SE Embedded.   Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5823</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="90" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5824</Title>
      <Notes>
         <Note Audience="All" Ordinal="90" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5824</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="91" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5825</Title>
      <Notes>
         <Note Audience="All" Ordinal="91" Title="Details" Type="Details">Vulnerability in the Java SE, JRockit, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Java SE, JRockit, Java SE Embedded.   Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5825</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="92" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5826</Title>
      <Notes>
         <Note Audience="All" Ordinal="92" Title="Details" Type="Details">Vulnerability in the Oracle Transportation Management component of Oracle Supply Chain Products Suite (subcomponent: Install / Installation).  Supported versions that are affected are 6.3 and  6.3.1. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Transportation Management.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5826</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1991V-6.3</ProductID>
            <ProductID>P-1991V-6.3.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-1991V-6.3</ProductID>
            <ProductID>P-1991V-6.3.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="93" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5827</Title>
      <Notes>
         <Note Audience="All" Ordinal="93" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Storage Management).  Supported versions that are affected are EM Base Platform: 10.2.0.5, 11.1.0.1&lt;br/&gt;
EM DB Control: 11.1.0.7, 11.2.0.2 and  11.2.0.3&lt;br/&gt;
EM Plugin for DB: 12.1.0.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Enterprise Manager Base Platform accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5827</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1366V-EM Base Platform: 10.2.0.5</ProductID>
            <ProductID>P-1366V-11.1.0.1EM DB Control: 11.1.0.7</ProductID>
            <ProductID>P-1366V-11.2.0.2</ProductID>
            <ProductID>P-1366V-11.2.0.3EM Plugin for DB: 12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-1366V-EM Base Platform: 10.2.0.5</ProductID>
            <ProductID>P-1366V-11.1.0.1EM DB Control: 11.1.0.7</ProductID>
            <ProductID>P-1366V-11.2.0.2</ProductID>
            <ProductID>P-1366V-11.2.0.3EM Plugin for DB: 12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="94" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5828</Title>
      <Notes>
         <Note Audience="All" Ordinal="94" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Storage Management).  Supported versions that are affected are EM Base Platform: 10.2.0.5, 11.1.0.1&lt;br/&gt;EM DB Control: 11.1.0.7, 11.2.0.2, 11.2.0.3&lt;br/&gt;EM Plugin for DB: 12.1.0.2 and  12.1.0.3. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to all Enterprise Manager Base Platform accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P+/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5828</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1366V-EM Base Platform: 10.2.0.5</ProductID>
            <ProductID>P-1366V-11.1.0.1EM DB Control: 11.1.0.7</ProductID>
            <ProductID>P-1366V-11.2.0.2</ProductID>
            <ProductID>P-1366V-11.2.0.3EM Plugin for DB: 12.1.0.2</ProductID>
            <ProductID>P-1366V-12.1.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-1366V-EM Base Platform: 10.2.0.5</ProductID>
            <ProductID>P-1366V-11.1.0.1EM DB Control: 11.1.0.7</ProductID>
            <ProductID>P-1366V-11.2.0.2</ProductID>
            <ProductID>P-1366V-11.2.0.3EM Plugin for DB: 12.1.0.2</ProductID>
            <ProductID>P-1366V-12.1.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="95" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5829</Title>
      <Notes>
         <Note Audience="All" Ordinal="95" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: 2D).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5829</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="96" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5830</Title>
      <Notes>
         <Note Audience="All" Ordinal="96" Title="Details" Type="Details">Vulnerability in the Java SE, JRockit, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JRockit R28.2.8 and earlier, JRockit R27.7.6 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5830</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JRockit R28.2.8 and earlier</ProductID>
            <ProductID>P-856V-JRockit R27.7.6 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="97" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5831</Title>
      <Notes>
         <Note Audience="All" Ordinal="97" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE, Java SE Embedded accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5831</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="98" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5832</Title>
      <Notes>
         <Note Audience="All" Ordinal="98" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier and  Java SE Embedded 7u40 and earlier. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 9.3 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5832</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>9.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="99" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5835</Title>
      <Notes>
         <Note Audience="All" Ordinal="99" Title="Details" Type="Details">Vulnerability in the Siebel UI Framework component of Oracle Siebel CRM (subcomponent: Open_UI).  Supported versions that are affected are 8.1.1 and  8.2.2. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Siebel UI Framework accessible data as well as  read access to a subset of Siebel UI Framework accessible data and ability to cause a partial denial of service (partial DOS) of Siebel UI Framework.  CVSS Base Score 6.8 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:P/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5835</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.8</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:P/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-9011V-8.1.1</ProductID>
            <ProductID>P-9011V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="100" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5836</Title>
      <Notes>
         <Note Audience="All" Ordinal="100" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Business Interlink).  Supported versions that are affected are 8.51, 8.52 and  8.53. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5836</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
            <ProductID>P-5085V-8.53</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
            <ProductID>P-5085V-8.53</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="101" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5837</Title>
      <Notes>
         <Note Audience="All" Ordinal="101" Title="Details" Type="Details">Vulnerability in the Oracle Health Sciences InForm component of Oracle Industry Applications (subcomponent: Cognos).  Supported versions that are affected are 4.6 SP0, 4.6 SP0a-c, 4.6 SP1, 4.6 SP1a-c, 4.6 SP2, 4.6 SP2a-c, 5.0 SP0, 5.0 SP0a, 5.0 SP1, 5.0 SP1a-b, 5.0.3 and  5.0.4. Very difficult to exploit vulnerability allows successful authenticated network attacks via None.  Successful attack of this vulnerability can result in unauthorized  read access to all Oracle Health Sciences InForm accessible data.  CVSS Base Score 2.1 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:H/Au:S/C:P+/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5837</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9132V-4.6 SP0</ProductID>
            <ProductID>P-9132V-4.6 SP0a-c</ProductID>
            <ProductID>P-9132V-4.6 SP1</ProductID>
            <ProductID>P-9132V-4.6 SP1a-c</ProductID>
            <ProductID>P-9132V-4.6 SP2</ProductID>
            <ProductID>P-9132V-4.6 SP2a-c</ProductID>
            <ProductID>P-9132V-5.0 SP0</ProductID>
            <ProductID>P-9132V-5.0 SP0a</ProductID>
            <ProductID>P-9132V-5.0 SP1</ProductID>
            <ProductID>P-9132V-5.0 SP1a-b</ProductID>
            <ProductID>P-9132V-5.0.3</ProductID>
            <ProductID>P-9132V-5.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.1</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-9132V-4.6 SP0</ProductID>
            <ProductID>P-9132V-4.6 SP0a-c</ProductID>
            <ProductID>P-9132V-4.6 SP1</ProductID>
            <ProductID>P-9132V-4.6 SP1a-c</ProductID>
            <ProductID>P-9132V-4.6 SP2</ProductID>
            <ProductID>P-9132V-4.6 SP2a-c</ProductID>
            <ProductID>P-9132V-5.0 SP0</ProductID>
            <ProductID>P-9132V-5.0 SP0a</ProductID>
            <ProductID>P-9132V-5.0 SP1</ProductID>
            <ProductID>P-9132V-5.0 SP1a-b</ProductID>
            <ProductID>P-9132V-5.0.3</ProductID>
            <ProductID>P-9132V-5.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="102" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5838</Title>
      <Notes>
         <Note Audience="All" Ordinal="102" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries).  Supported versions that are affected are Java SE 7u25 and earlier and  Java SE Embedded 7u25 and earlier. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 9.3 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5838</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u25 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u25 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>9.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u25 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u25 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="103" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5839</Title>
      <Notes>
         <Note Audience="All" Ordinal="103" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle and Sun Systems Products Suite (subcomponent: Oracle Java Web Console).   The supported version that is affected is 10. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5839</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-10006V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="104" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5840</Title>
      <Notes>
         <Note Audience="All" Ordinal="104" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java SE, Java SE Embedded accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5840</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="105" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5841</Title>
      <Notes>
         <Note Audience="All" Ordinal="105" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Portal).  Supported versions that are affected are 8.51, 8.52 and  8.53. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise PeopleTools accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5841</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
            <ProductID>P-5085V-8.53</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-5085V-8.51</ProductID>
            <ProductID>P-5085V-8.52</ProductID>
            <ProductID>P-5085V-8.53</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="106" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5842</Title>
      <Notes>
         <Note Audience="All" Ordinal="106" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5842</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="107" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5843</Title>
      <Notes>
         <Note Audience="All" Ordinal="107" Title="Details" Type="Details">Vulnerability in the Java SE, JavaFX, Java SE Embedded component of Oracle Java SE (subcomponent: 2D).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, JavaFX 2.2.40 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:L/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5843</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JavaFX 2.2.40 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>10.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-JavaFX 2.2.40 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="108" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5844</Title>
      <Notes>
         <Note Audience="All" Ordinal="108" Title="Details" Type="Details">Vulnerability in the Java SE, JavaFX component of Oracle Java SE (subcomponent: JavaFX).  Supported versions that are affected are Java SE 7u40 and earlier and  JavaFX 2.2.40 and earlier. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 9.3 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5844</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-JavaFX 2.2.40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>9.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-JavaFX 2.2.40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="109" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5845</Title>
      <Notes>
         <Note Audience="All" Ordinal="109" Title="Details" Type="Details">Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Administration).  Supported versions that are affected are 5.2.1 and  6.0. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle iLearning accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5845</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-902V-5.2.1</ProductID>
            <ProductID>P-902V-6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-902V-5.2.1</ProductID>
            <ProductID>P-902V-6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="110" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5846</Title>
      <Notes>
         <Note Audience="All" Ordinal="110" Title="Details" Type="Details">Vulnerability in the Java SE, JavaFX component of Oracle Java SE (subcomponent: JavaFX).  Supported versions that are affected are Java SE 7u40 and earlier and  JavaFX 2.2.40 and earlier. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 9.3 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5846</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-JavaFX 2.2.40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>9.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-JavaFX 2.2.40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="111" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5847</Title>
      <Notes>
         <Note Audience="All" Ordinal="111" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise HRMS eCompensation component of Oracle PeopleSoft Products (subcomponent: eCompensation).  Supported versions that are affected are 9.1 and  9.2. Easily exploitable vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of PeopleSoft Enterprise HRMS eCompensation accessible data.  CVSS Base Score 4.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:S/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5847</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5046V-9.1</ProductID>
            <ProductID>P-5046V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.0</BaseScore>
            <Vector>AV:N/AC:L/Au:S/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-5046V-9.1</ProductID>
            <ProductID>P-5046V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="112" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5848</Title>
      <Notes>
         <Note Audience="All" Ordinal="112" Title="Details" Type="Details">Vulnerability in the Java SE, JavaFX component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier and  JavaFX 2.2.40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Java SE, JavaFX accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 5.0 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5848</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-JavaFX 2.2.40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-JavaFX 2.2.40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="113" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5849</Title>
      <Notes>
         <Note Audience="All" Ordinal="113" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: AWT).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier and  Java SE Embedded 7u40 and earlier. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java SE, Java SE Embedded accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 4.3 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5849</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="114" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5850</Title>
      <Notes>
         <Note Audience="All" Ordinal="114" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Libraries).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier and  Java SE Embedded 7u40 and earlier. Difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 9.3 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:M/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5850</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>9.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE 5.0u51 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="115" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5851</Title>
      <Notes>
         <Note Audience="All" Ordinal="115" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: JAXP).  Supported versions that are affected are Java SE 7u40 and earlier and  Java SE Embedded 7u40 and earlier. Easily exploitable vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java SE, Java SE Embedded accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5851</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="116" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5852</Title>
      <Notes>
         <Note Audience="All" Ordinal="116" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Deployment).  Supported versions that are affected are Java SE 7u40 and earlier, Java SE 6u60 and earlier and  Java SE Embedded 7u40 and earlier. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: Applies to installation process on client deployment of Java. CVSS Base Score 7.6 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:N/AC:H/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5852</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>7.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-Java SE 6u60 and earlier</ProductID>
            <ProductID>P-856V-Java SE Embedded 7u40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="117" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5854</Title>
      <Notes>
         <Note Audience="All" Ordinal="117" Title="Details" Type="Details">Vulnerability in the Java SE, JavaFX component of Oracle Java SE (subcomponent: JavaFX).  Supported versions that are affected are Java SE 7u40 and earlier and  JavaFX 2.2.40 and earlier. Very difficult to exploit vulnerability allows successful unauthenticated network attacks via multiple protocols.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Java SE, JavaFX accessible data.   Note: Applies to client deployment of Java only. This vulnerability can be exploited only through sandboxed Java Web Start applications and sandboxed Java applets. CVSS Base Score 2.6 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:H/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5854</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-JavaFX 2.2.40 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>2.6</BaseScore>
            <Vector>AV:N/AC:H/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-856V-Java SE 7u40 and earlier</ProductID>
            <ProductID>P-856V-JavaFX 2.2.40 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="118" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5856</Title>
      <Notes>
         <Note Audience="All" Ordinal="118" Title="Details" Type="Details">Vulnerability in the Oracle Health Sciences InForm component of Oracle Industry Applications (subcomponent: Web).  Supported versions that are affected are 4.5 SP3, 4.5 SP3a-k, 4.6 SP0, 4.6 SP0a-c, 4.6 SP1, 4.6 SP1a-c, 4.6 SP2, 4.6 SP2a-c, 5.0 SP0, 5.0 SP0a, 5.0 SP1, 5.0 SP1a-b, 5.5 SP0, 5.5 SP0b, 5.5.1 and  6.0.0. Very difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Health Sciences InForm accessible data as well as  read access to a subset of Oracle Health Sciences InForm accessible data.  CVSS Base Score 3.6 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5856</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9132V-4.5 SP3</ProductID>
            <ProductID>P-9132V-4.5 SP3a-k</ProductID>
            <ProductID>P-9132V-4.6 SP0</ProductID>
            <ProductID>P-9132V-4.6 SP0a-c</ProductID>
            <ProductID>P-9132V-4.6 SP1</ProductID>
            <ProductID>P-9132V-4.6 SP1a-c</ProductID>
            <ProductID>P-9132V-4.6 SP2</ProductID>
            <ProductID>P-9132V-4.6 SP2a-c</ProductID>
            <ProductID>P-9132V-5.0 SP0</ProductID>
            <ProductID>P-9132V-5.0 SP0a</ProductID>
            <ProductID>P-9132V-5.0 SP1</ProductID>
            <ProductID>P-9132V-5.0 SP1a-b</ProductID>
            <ProductID>P-9132V-5.5 SP0</ProductID>
            <ProductID>P-9132V-5.5 SP0b</ProductID>
            <ProductID>P-9132V-5.5.1</ProductID>
            <ProductID>P-9132V-6.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.6</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-9132V-4.5 SP3</ProductID>
            <ProductID>P-9132V-4.5 SP3a-k</ProductID>
            <ProductID>P-9132V-4.6 SP0</ProductID>
            <ProductID>P-9132V-4.6 SP0a-c</ProductID>
            <ProductID>P-9132V-4.6 SP1</ProductID>
            <ProductID>P-9132V-4.6 SP1a-c</ProductID>
            <ProductID>P-9132V-4.6 SP2</ProductID>
            <ProductID>P-9132V-4.6 SP2a-c</ProductID>
            <ProductID>P-9132V-5.0 SP0</ProductID>
            <ProductID>P-9132V-5.0 SP0a</ProductID>
            <ProductID>P-9132V-5.0 SP1</ProductID>
            <ProductID>P-9132V-5.0 SP1a-b</ProductID>
            <ProductID>P-9132V-5.5 SP0</ProductID>
            <ProductID>P-9132V-5.5 SP0b</ProductID>
            <ProductID>P-9132V-5.5.1</ProductID>
            <ProductID>P-9132V-6.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="119" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5857</Title>
      <Notes>
         <Note Audience="All" Ordinal="119" Title="Details" Type="Details">Vulnerability in the Oracle Health Sciences InForm component of Oracle Industry Applications (subcomponent: Web).  Supported versions that are affected are 4.5 SP3, 4.5 SP3a-k, 4.6 SP0, 4.6 SP0a-c, 4.6 SP1, 4.6 SP1a-c, 4.6 SP2, 4.6 SP2a-c, 5.0 SP0, 5.0 SP0a, 5.0 SP1 and  5.0 SP1a-b. Very difficult to exploit vulnerability allows successful authenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Oracle Health Sciences InForm accessible data as well as  read access to a subset of Oracle Health Sciences InForm accessible data.  CVSS Base Score 3.6 (Confidentiality and Integrity impacts).  CVSS V2 Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:N).  Oracle Vector: (AV:N/AC:H/Au:S/C:P/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5857</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9132V-4.5 SP3</ProductID>
            <ProductID>P-9132V-4.5 SP3a-k</ProductID>
            <ProductID>P-9132V-4.6 SP0</ProductID>
            <ProductID>P-9132V-4.6 SP0a-c</ProductID>
            <ProductID>P-9132V-4.6 SP1</ProductID>
            <ProductID>P-9132V-4.6 SP1a-c</ProductID>
            <ProductID>P-9132V-4.6 SP2</ProductID>
            <ProductID>P-9132V-4.6 SP2a-c</ProductID>
            <ProductID>P-9132V-5.0 SP0</ProductID>
            <ProductID>P-9132V-5.0 SP0a</ProductID>
            <ProductID>P-9132V-5.0 SP1</ProductID>
            <ProductID>P-9132V-5.0 SP1a-b</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>3.6</BaseScore>
            <Vector>AV:N/AC:H/Au:S/C:P/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-9132V-4.5 SP3</ProductID>
            <ProductID>P-9132V-4.5 SP3a-k</ProductID>
            <ProductID>P-9132V-4.6 SP0</ProductID>
            <ProductID>P-9132V-4.6 SP0a-c</ProductID>
            <ProductID>P-9132V-4.6 SP1</ProductID>
            <ProductID>P-9132V-4.6 SP1a-c</ProductID>
            <ProductID>P-9132V-4.6 SP2</ProductID>
            <ProductID>P-9132V-4.6 SP2a-c</ProductID>
            <ProductID>P-9132V-5.0 SP0</ProductID>
            <ProductID>P-9132V-5.0 SP0a</ProductID>
            <ProductID>P-9132V-5.0 SP1</ProductID>
            <ProductID>P-9132V-5.0 SP1a-b</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="120" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5859</Title>
      <Notes>
         <Note Audience="All" Ordinal="120" Title="Details" Type="Details">Vulnerability in the Instantis EnterpriseTrack component of Oracle Primavera Products Suite (subcomponent: Instantis EnterpriseTrack).  Supported versions that are affected are 8.0.6 and  8.5. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  read access to a subset of Instantis EnterpriseTrack accessible data.  CVSS Base Score 5.0 (Confidentiality impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).  Oracle Vector: (AV:N/AC:L/Au:N/C:P/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5859</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10563V-8.0.6</ProductID>
            <ProductID>P-10563V-8.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:P/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-10563V-8.0.6</ProductID>
            <ProductID>P-10563V-8.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="121" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5861</Title>
      <Notes>
         <Note Audience="All" Ordinal="121" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle and Sun Systems Products Suite (subcomponent: Kernel/KSSL).   The supported version that is affected is 11.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via SSL.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 4.3 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5861</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-10006V-11.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="122" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5862</Title>
      <Notes>
         <Note Audience="All" Ordinal="122" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle and Sun Systems Products Suite (subcomponent: CPU performance counters (CPC) drivers).  Supported versions that are affected are 10 and  11.1. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 4.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5862</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="123" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5863</Title>
      <Notes>
         <Note Audience="All" Ordinal="123" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle and Sun Systems Products Suite (subcomponent: IPS repository daemon).   The supported version that is affected is 11.1. Difficult to exploit vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized  update, insert or delete access to some Solaris accessible data.  CVSS Base Score 4.3 (Integrity impacts).  CVSS V2 Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).  Oracle Vector: (AV:N/AC:M/Au:N/C:N/I:P/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5863</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.3</BaseScore>
            <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-10006V-11.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="124" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5864</Title>
      <Notes>
         <Note Audience="All" Ordinal="124" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle and Sun Systems Products Suite (subcomponent: USB hub driver).  Supported versions that are affected are 10 and  11.1. Easily exploitable vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS).  CVSS Base Score 4.9 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).  Oracle Vector: (AV:L/AC:L/Au:N/C:N/I:N/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5864</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>4.9</BaseScore>
            <Vector>AV:L/AC:L/Au:N/C:N/I:N/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-10006V-10</ProductID>
            <ProductID>P-10006V-11.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="125" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5865</Title>
      <Notes>
         <Note Audience="All" Ordinal="125" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle and Sun Systems Products Suite (subcomponent: Utility/User administration).   The supported version that is affected is 11.1. Easily exploitable vulnerability requiring logon to Operating System plus additional login/authentication to component or subcomponent.  Successful attack of this vulnerability can escalate attacker privileges resulting in unauthorized ability to cause a partial denial of service (partial DOS) of Solaris.  CVSS Base Score 1.7 (Availability impacts).  CVSS V2 Vector: (AV:L/AC:L/Au:S/C:N/I:N/A:P).  Oracle Vector: (AV:L/AC:L/Au:S/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5865</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>1.7</BaseScore>
            <Vector>AV:L/AC:L/Au:S/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-10006V-11.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="126" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5866</Title>
      <Notes>
         <Note Audience="All" Ordinal="126" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle and Sun Systems Products Suite (subcomponent: Kernel).   The supported version that is affected is 11.1. Very difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System hang or frequently repeatable crash (complete DOS) as well as  update, insert or delete access to some Solaris accessible data and  read access to a subset of Solaris accessible data.  CVSS Base Score 5.2 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:H/Au:N/C:P/I:P/A:C).  Oracle Vector: (AV:L/AC:H/Au:N/C:P/I:P/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5866</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.2</BaseScore>
            <Vector>AV:L/AC:H/Au:N/C:P/I:P/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-10006V-11.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="127" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5867</Title>
      <Notes>
         <Note Audience="All" Ordinal="127" Title="Details" Type="Details">Vulnerability in the Siebel Core - Server Infrastructure component of Oracle Siebel CRM (subcomponent: SISNAPI &amp; Network Infrastructu).  Supported versions that are affected are 8.1.1 and  8.2.2. Easily exploitable vulnerability allows successful unauthenticated network attacks via HTTP.  Successful attack of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Siebel Core - Server Infrastructure.  CVSS Base Score 5.0 (Availability impacts).  CVSS V2 Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).  Oracle Vector: (AV:N/AC:L/Au:N/C:N/I:N/A:P).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5867</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9004V-8.1.1</ProductID>
            <ProductID>P-9004V-8.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>5.0</BaseScore>
            <Vector>AV:N/AC:L/Au:N/C:N/I:N/A:P</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUOct2013</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/cpuoct2013-1899837.html</URL>
            <ProductID>P-9004V-8.1.1</ProductID>
            <ProductID>P-9004V-8.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
</cvrf:cvrfdoc>
