<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/2967710.xsl"?>
<?xml-stylesheet type="text/css" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/2967708.css"?>
<cvrf:cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle Critical Patch Update Advisory - April 2017 - Oracle CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle Critical Patch Update Advisory</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>CPUApr2017</ID>
      </Identification>
      <Status>Final</Status>
      <Version>1.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>1.0</Number>
            <Date>2017-04-18T13:00:00-07:00</Date>
            <Description>Initial Distribution</Description>
         </Revision>
      </RevisionHistory>
      <InitialReleaseDate>2017-04-18T13:00:00-07:00</InitialReleaseDate>
      <CurrentReleaseDate>2017-04-18T13:00:00-07:00</CurrentReleaseDate>
   </DocumentTracking>
   <DocumentNotes>
      <Note Audience="All" Ordinal="1" Title="Summary" Type="Summary" xml:lang="en">This document contains descriptions of Oracle product security vulnerabilities which have had fixes released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including fix distribution information can be found at the Oracle sites referenced in this document.</Note>
   </DocumentNotes>
   <DocumentDistribution>This document is published at: http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/3681811.xml</DocumentDistribution>
   <DocumentReferences>
      <Reference Type="External">
         <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
   <Acknowledgments>
      <Acknowledgment>
         <Name>Abhishek Nandawat</Name>
         <Organization>Abhishek Nandawat</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Adam Willard</Name>
         <Organization>Blue Canopy</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Akshay Jain</Name>
         <Organization>Akshay Jain</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Alexey Tyurin</Name>
         <Organization>ERPScan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Andrea Micalizzi aka rgod, working with Trend Micro's Zero Day Initiative</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Andrew Gill</Name>
         <Organization>Pentest Limited</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Arun Babu</Name>
         <Organization>ValueMentor Infosec Pvt. Ltd</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Binoy Koonammavu</Name>
         <Organization>ValueMentor Infosec Pvt. Ltd</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Can Demirel and Faruk Unal of Biznet Bilisim A.S</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Thijs Alkemade of Computest</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Cédric Bühler</Name>
         <Organization>Cédric Bühler</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Daniël van Eeden</Name>
         <Organization>Daniël van Eeden</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>David Litchfield formerly of Google</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Deniz Cevik</Name>
         <Organization>Biznet Bilisim A.S.</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Devin Rosenbauer</Name>
         <Organization>Identity Works LLC</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Dmitrii Iudin aka @ret5et</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Dmitry Chastuhin</Name>
         <Organization>ERPScan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Eric Gruber</Name>
         <Organization>Netspi</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Florian Bogner</Name>
         <Organization>Florian Bogner</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Gaston Traberg</Name>
         <Organization>Onapsis</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Hamdi Charfeddine</Name>
         <Organization>Tunisian WhiteHat Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Hanno Böck</Name>
         <Organization>Hanno Böck</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Harsh Joshi of Infomenia Technologies</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ivan Chalykin</Name>
         <Organization>ERPScan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jacob Baines</Name>
         <Organization>Tenable Network Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jakub Palaczynski</Name>
         <Organization>ING Services Polska</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>James Forshaw</Name>
         <Organization>James Forshaw</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jann Horn</Name>
         <Organization>Jann Horn</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jasmin Landry</Name>
         <Organization>Jasmin Landry</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jason Bertman</Name>
         <Organization>Jason Bertman</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jeffrey Walton</Name>
         <Organization>Jeffrey Walton</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jhayz Rubio</Name>
         <Organization>Jhayz Rubio</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>John S Andersen</Name>
         <Organization>Intel</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Jussi</Name>
         <Organization>CERT-FI</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Khai Tran formerly of Netspi</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Khajornchol Puwarang</Name>
         <Organization>Mindterra Red Team</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Li Qiang of the Qihoo 360 Gear Team</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Lionel Debroux</Name>
         <Organization>Lionel Debroux</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>MMakhil</Name>
         <Organization>MMakhil</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mala</Name>
         <Organization>Mala</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Manich Koomsusi</Name>
         <Organization>Mindterra Red Team</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Marcin Zięba</Name>
         <Organization>Prevenity</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mat Werber</Name>
         <Organization>Amazon Web Services IT Security</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mateusz Jurczyk of Google Project Zero</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Matias Mevied</Name>
         <Organization>Onapsis</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Md. Nur A Alam Dipu</Name>
         <Organization>Md. Nur A Alam Dipu</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mehmet Nurcan</Name>
         <Organization>Mehmet Nurcan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mickey Shkatov</Name>
         <Organization>Intel</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mohammed Almouty</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Mohammed Saty</Name>
         <Organization>PricewaterhouseCoopers</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Moritz Bechler</Name>
         <Organization>Moritz Bechler (eenterphace.org)</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Muhammad Uwais</Name>
         <Organization>Muhammad Uwais</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Muhammad nurnobi of Serverghosts</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Nada Alnoaimi</Name>
         <Organization>Saudi Aramco</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Nadezhda Krivdyuk</Name>
         <Organization>ERPScan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>An Anonymous researcher via Beyond Security's SecuriTeam Secure Disclosure Program</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Or Hanuka</Name>
         <Organization>Motorola Solutions</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Peter Kostiuk</Name>
         <Organization>Salesforce.com</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Renjith TC</Name>
         <Organization>ValueMentor Infosec Pvt. Ltd</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Rodrigo Marcos</Name>
         <Organization>Secforce</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Roman Shalymov</Name>
         <Organization>ERPScan</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Spyridon Chatzimichail of OTE Hellenic Telecommunications Organization S.A.</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sreedeep.Ck Alavil of Kerala Police Cyber Dome Volunteers Commander</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Suleman Malik</Name>
         <Organization>Suleman Malik</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Sumit Sahoo (54H00)</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Suraj Khetani</Name>
         <Organization>Gulf Business Machines</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Suvadip Kar</Name>
         <Organization>Suvadip Kar</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Tansel Çetin</Name>
         <Organization>Tansel Çetin</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Tawatchai Pinsuwan</Name>
         <Organization>Mindterra Red Team</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Teemu Kääriäinen (Nixu)</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Tzachy Horesh</Name>
         <Organization>Motorola Solutions</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Ubais PK</Name>
         <Organization>EY Global Delivery Services</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>William Roberts</Name>
         <Organization>Intel</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Xiejingwei Fei</Name>
         <Organization>FINRA</Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>Zuozhi Fan formerly of Alibaba</Name>
         <Organization></Organization>
      </Acknowledgment>
      <Acknowledgment>
         <Name>loopx9</Name>
         <Organization>loopx9</Organization>
      </Acknowledgment>
   </Acknowledgments>
   <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Name="Oracle" Type="Vendor">
         <Branch Name="Oracle Berkeley DB" Type="Product Family">
            <Branch Name="Oracle Berkeley DB" Type="Product Name">
               <Branch Name="Prior to 6.2.32" Type="Product Version">
                  <FullProductName ProductID="P-2051V-Prior to 6.2.32">Oracle Berkeley DB Version Prior to 6.2.32</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Commerce" Type="Product Family">
            <Branch Name="Commerce Guided Search / Oracle Commerce Experience Manager" Type="Product Name">
               <Branch Name="11.0" Type="Product Version">
                  <FullProductName ProductID="P-9633V-11.0">Commerce Guided Search / Oracle Commerce Experience Manager Version 11.0</FullProductName>
               </Branch>
               <Branch Name="11.1" Type="Product Version">
                  <FullProductName ProductID="P-9633V-11.1">Commerce Guided Search / Oracle Commerce Experience Manager Version 11.1</FullProductName>
               </Branch>
               <Branch Name="11.2" Type="Product Version">
                  <FullProductName ProductID="P-9633V-11.2">Commerce Guided Search / Oracle Commerce Experience Manager Version 11.2</FullProductName>
               </Branch>
               <Branch Name="6.1.4" Type="Product Version">
                  <FullProductName ProductID="P-9633V-6.1.4">Commerce Guided Search / Oracle Commerce Experience Manager Version 6.1.4</FullProductName>
               </Branch>
               <Branch Name="6.2.2" Type="Product Version">
                  <FullProductName ProductID="P-9633V-6.2.2">Commerce Guided Search / Oracle Commerce Experience Manager Version 6.2.2</FullProductName>
               </Branch>
               <Branch Name="6.3.0" Type="Product Version">
                  <FullProductName ProductID="P-9633V-6.3.0">Commerce Guided Search / Oracle Commerce Experience Manager Version 6.3.0</FullProductName>
               </Branch>
               <Branch Name="6.4.1.2" Type="Product Version">
                  <FullProductName ProductID="P-9633V-6.4.1.2">Commerce Guided Search / Oracle Commerce Experience Manager Version 6.4.1.2</FullProductName>
               </Branch>
               <Branch Name="6.5.0" Type="Product Version">
                  <FullProductName ProductID="P-9633V-6.5.0">Commerce Guided Search / Oracle Commerce Experience Manager Version 6.5.0</FullProductName>
               </Branch>
               <Branch Name="6.5.1" Type="Product Version">
                  <FullProductName ProductID="P-9633V-6.5.1">Commerce Guided Search / Oracle Commerce Experience Manager Version 6.5.1</FullProductName>
               </Branch>
               <Branch Name="6.5.2" Type="Product Version">
                  <FullProductName ProductID="P-9633V-6.5.2">Commerce Guided Search / Oracle Commerce Experience Manager Version 6.5.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Communications Applications" Type="Product Family">
            <Branch Name="Communications ASAP" Type="Product Name">
               <Branch Name="7.0" Type="Product Version">
                  <FullProductName ProductID="P-2260V-7.0">Communications ASAP Version 7.0</FullProductName>
               </Branch>
               <Branch Name="7.2" Type="Product Version">
                  <FullProductName ProductID="P-2260V-7.2">Communications ASAP Version 7.2</FullProductName>
               </Branch>
               <Branch Name="7.3" Type="Product Version">
                  <FullProductName ProductID="P-2260V-7.3">Communications ASAP Version 7.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Network Integrity" Type="Product Name">
               <Branch Name="7.2.4" Type="Product Version">
                  <FullProductName ProductID="P-4491V-7.2.4">Communications Network Integrity Version 7.2.4</FullProductName>
               </Branch>
               <Branch Name="7.3.0" Type="Product Version">
                  <FullProductName ProductID="P-4491V-7.3.0">Communications Network Integrity Version 7.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Service Broker Engineered System Edition" Type="Product Name">
               <Branch Name="6.0" Type="Product Version">
                  <FullProductName ProductID="P-9056V-6.0">Communications Service Broker Engineered System Edition Version 6.0</FullProductName>
               </Branch>
               <Branch Name="6.1" Type="Product Version">
                  <FullProductName ProductID="P-9056V-6.1">Communications Service Broker Engineered System Edition Version 6.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Session Border Controller" Type="Product Name">
               <Branch Name="SCZ7.2.0" Type="Product Version">
                  <FullProductName ProductID="P-10750V-SCZ7.2.0">Communications Session Border Controller Version SCZ7.2.0</FullProductName>
               </Branch>
               <Branch Name="SCZ7.3.0" Type="Product Version">
                  <FullProductName ProductID="P-10750V-SCZ7.3.0">Communications Session Border Controller Version SCZ7.3.0</FullProductName>
               </Branch>
               <Branch Name="SCZ7.4.0" Type="Product Version">
                  <FullProductName ProductID="P-10750V-SCZ7.4.0">Communications Session Border Controller Version SCZ7.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Security Gateway" Type="Product Name">
               <Branch Name="3.0.0" Type="Product Version">
                  <FullProductName ProductID="P-10755V-3.0.0">Communications Security Gateway Version 3.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Communications Policy Management" Type="Product Name">
               <Branch Name="12.2" Type="Product Version">
                  <FullProductName ProductID="P-10900V-12.2">Communications Policy Management Version 12.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Database Server" Type="Product Family">
            <Branch Name="Oracle Database" Type="Product Name">
               <Branch Name="11.2.0.4" Type="Product Version">
                  <FullProductName ProductID="P-5V-11.2.0.4">Oracle Database Version 11.2.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-5V-12.1.0.2">Oracle Database Version 12.1.0.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="SQL*Plus" Type="Product Name">
               <Branch Name="11.2.0.4" Type="Product Version">
                  <FullProductName ProductID="P-50V-11.2.0.4">SQL*Plus Version 11.2.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0.2" Type="Product Version">
                  <FullProductName ProductID="P-50V-12.1.0.2">SQL*Plus Version 12.1.0.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle E-Business Suite" Type="Product Family">
            <Branch Name="Marketing" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.1.1">Marketing Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.1.2">Marketing Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.1.3">Marketing Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.2.3">Marketing Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.2.4">Marketing Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.2.5">Marketing Version 12.2.5</FullProductName>
               </Branch>
               <Branch Name="12.2.6" Type="Product Version">
                  <FullProductName ProductID="P-229V-12.2.6">Marketing Version 12.2.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Scripting" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-433V-12.1.1">Scripting Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-433V-12.1.2">Scripting Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-433V-12.1.3">Scripting Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-433V-12.2.3">Scripting Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-433V-12.2.4">Scripting Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-433V-12.2.5">Scripting Version 12.2.5</FullProductName>
               </Branch>
               <Branch Name="12.2.6" Type="Product Version">
                  <FullProductName ProductID="P-433V-12.2.6">Scripting Version 12.2.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Payroll" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-506V-12.1.1">Payroll Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-506V-12.1.2">Payroll Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-506V-12.1.3">Payroll Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-506V-12.2.3">Payroll Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-506V-12.2.4">Payroll Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-506V-12.2.5">Payroll Version 12.2.5</FullProductName>
               </Branch>
               <Branch Name="12.2.6" Type="Product Version">
                  <FullProductName ProductID="P-506V-12.2.6">Payroll Version 12.2.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Application Object Library" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-510V-12.1.3">Application Object Library Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-510V-12.2.3">Application Object Library Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-510V-12.2.4">Application Object Library Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-510V-12.2.5">Application Object Library Version 12.2.5</FullProductName>
               </Branch>
               <Branch Name="12.2.6" Type="Product Version">
                  <FullProductName ProductID="P-510V-12.2.6">Application Object Library Version 12.2.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Advanced Outbound Telephony" Type="Product Name">
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-785V-12.2.3">Advanced Outbound Telephony Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-785V-12.2.4">Advanced Outbound Telephony Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-785V-12.2.5">Advanced Outbound Telephony Version 12.2.5</FullProductName>
               </Branch>
               <Branch Name="12.2.6" Type="Product Version">
                  <FullProductName ProductID="P-785V-12.2.6">Advanced Outbound Telephony Version 12.2.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="iReceivables" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-1106V-12.1.1">iReceivables Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-1106V-12.1.2">iReceivables Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1106V-12.1.3">iReceivables Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-1106V-12.2.3">iReceivables Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-1106V-12.2.4">iReceivables Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-1106V-12.2.5">iReceivables Version 12.2.5</FullProductName>
               </Branch>
               <Branch Name="12.2.6" Type="Product Version">
                  <FullProductName ProductID="P-1106V-12.2.6">iReceivables Version 12.2.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Customer Interaction History" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.1.1">Customer Interaction History Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.1.2">Customer Interaction History Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1374V-12.1.3">Customer Interaction History Version 12.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="One-to-One Fulfillment" Type="Product Name">
               <Branch Name="12.1.1" Type="Product Version">
                  <FullProductName ProductID="P-1379V-12.1.1">One-to-One Fulfillment Version 12.1.1</FullProductName>
               </Branch>
               <Branch Name="12.1.2" Type="Product Version">
                  <FullProductName ProductID="P-1379V-12.1.2">One-to-One Fulfillment Version 12.1.2</FullProductName>
               </Branch>
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1379V-12.1.3">One-to-One Fulfillment Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-1379V-12.2.3">One-to-One Fulfillment Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-1379V-12.2.4">One-to-One Fulfillment Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-1379V-12.2.5">One-to-One Fulfillment Version 12.2.5</FullProductName>
               </Branch>
               <Branch Name="12.2.6" Type="Product Version">
                  <FullProductName ProductID="P-1379V-12.2.6">One-to-One Fulfillment Version 12.2.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Applications Framework" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.1.3">Applications Framework Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.2.3">Applications Framework Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.2.4">Applications Framework Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.2.5">Applications Framework Version 12.2.5</FullProductName>
               </Branch>
               <Branch Name="12.2.6" Type="Product Version">
                  <FullProductName ProductID="P-1472V-12.2.6">Applications Framework Version 12.2.6</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="User Management" Type="Product Name">
               <Branch Name="12.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1475V-12.1.3">User Management Version 12.1.3</FullProductName>
               </Branch>
               <Branch Name="12.2.3" Type="Product Version">
                  <FullProductName ProductID="P-1475V-12.2.3">User Management Version 12.2.3</FullProductName>
               </Branch>
               <Branch Name="12.2.4" Type="Product Version">
                  <FullProductName ProductID="P-1475V-12.2.4">User Management Version 12.2.4</FullProductName>
               </Branch>
               <Branch Name="12.2.5" Type="Product Version">
                  <FullProductName ProductID="P-1475V-12.2.5">User Management Version 12.2.5</FullProductName>
               </Branch>
               <Branch Name="12.2.6" Type="Product Version">
                  <FullProductName ProductID="P-1475V-12.2.6">User Management Version 12.2.6</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Enterprise Manager Grid Control" Type="Product Family">
            <Branch Name="Enterprise Manager Base Platform" Type="Product Name">
               <Branch Name="12.1.0" Type="Product Version">
                  <FullProductName ProductID="P-1370V-12.1.0">Enterprise Manager Base Platform Version 12.1.0</FullProductName>
               </Branch>
               <Branch Name="13.1.0" Type="Product Version">
                  <FullProductName ProductID="P-1370V-13.1.0">Enterprise Manager Base Platform Version 13.1.0</FullProductName>
               </Branch>
               <Branch Name="13.2.0" Type="Product Version">
                  <FullProductName ProductID="P-1370V-13.2.0">Enterprise Manager Base Platform Version 13.2.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Financial Services Applications" Type="Product Family">
            <Branch Name="Financial Services Enterprise Financial Performance Analytics" Type="Product Name">
               <Branch Name="8.0.0 to 8.0.4" Type="Product Version">
                  <FullProductName ProductID="P-4279V-8.0.0 to 8.0.4">Financial Services Enterprise Financial Performance Analytics Version 8.0.0 to 8.0.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Profitability Management" Type="Product Name">
               <Branch Name="6.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5658V-6.0.0">Financial Services Profitability Management Version 6.0.0</FullProductName>
               </Branch>
               <Branch Name="6.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5658V-6.1.0">Financial Services Profitability Management Version 6.1.0</FullProductName>
               </Branch>
               <Branch Name="6.1.1" Type="Product Version">
                  <FullProductName ProductID="P-5658V-6.1.1">Financial Services Profitability Management Version 6.1.1</FullProductName>
               </Branch>
               <Branch Name="8.0.1" Type="Product Version">
                  <FullProductName ProductID="P-5658V-8.0.1">Financial Services Profitability Management Version 8.0.1</FullProductName>
               </Branch>
               <Branch Name="8.0.2" Type="Product Version">
                  <FullProductName ProductID="P-5658V-8.0.2">Financial Services Profitability Management Version 8.0.2</FullProductName>
               </Branch>
               <Branch Name="8.0.3" Type="Product Version">
                  <FullProductName ProductID="P-5658V-8.0.3">Financial Services Profitability Management Version 8.0.3</FullProductName>
               </Branch>
               <Branch Name="8.0.4" Type="Product Version">
                  <FullProductName ProductID="P-5658V-8.0.4">Financial Services Profitability Management Version 8.0.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Funds Transfer Pricing" Type="Product Name">
               <Branch Name="6.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5659V-6.0.0">Financial Services Funds Transfer Pricing Version 6.0.0</FullProductName>
               </Branch>
               <Branch Name="6.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5659V-6.1.0">Financial Services Funds Transfer Pricing Version 6.1.0</FullProductName>
               </Branch>
               <Branch Name="6.1.1" Type="Product Version">
                  <FullProductName ProductID="P-5659V-6.1.1">Financial Services Funds Transfer Pricing Version 6.1.1</FullProductName>
               </Branch>
               <Branch Name="8.0.1" Type="Product Version">
                  <FullProductName ProductID="P-5659V-8.0.1">Financial Services Funds Transfer Pricing Version 8.0.1</FullProductName>
               </Branch>
               <Branch Name="8.0.2" Type="Product Version">
                  <FullProductName ProductID="P-5659V-8.0.2">Financial Services Funds Transfer Pricing Version 8.0.2</FullProductName>
               </Branch>
               <Branch Name="8.0.3" Type="Product Version">
                  <FullProductName ProductID="P-5659V-8.0.3">Financial Services Funds Transfer Pricing Version 8.0.3</FullProductName>
               </Branch>
               <Branch Name="8.0.4" Type="Product Version">
                  <FullProductName ProductID="P-5659V-8.0.4">Financial Services Funds Transfer Pricing Version 8.0.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Asset Liability Management" Type="Product Name">
               <Branch Name="6.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5662V-6.0.0">Financial Services Asset Liability Management Version 6.0.0</FullProductName>
               </Branch>
               <Branch Name="6.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5662V-6.1.0">Financial Services Asset Liability Management Version 6.1.0</FullProductName>
               </Branch>
               <Branch Name="6.1.1" Type="Product Version">
                  <FullProductName ProductID="P-5662V-6.1.1">Financial Services Asset Liability Management Version 6.1.1</FullProductName>
               </Branch>
               <Branch Name="8.0.1" Type="Product Version">
                  <FullProductName ProductID="P-5662V-8.0.1">Financial Services Asset Liability Management Version 8.0.1</FullProductName>
               </Branch>
               <Branch Name="8.0.2" Type="Product Version">
                  <FullProductName ProductID="P-5662V-8.0.2">Financial Services Asset Liability Management Version 8.0.2</FullProductName>
               </Branch>
               <Branch Name="8.0.3" Type="Product Version">
                  <FullProductName ProductID="P-5662V-8.0.3">Financial Services Asset Liability Management Version 8.0.3</FullProductName>
               </Branch>
               <Branch Name="8.0.4" Type="Product Version">
                  <FullProductName ProductID="P-5662V-8.0.4">Financial Services Asset Liability Management Version 8.0.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Analytical Applications Infrastructure" Type="Product Name">
               <Branch Name="7.3.3" Type="Product Version">
                  <FullProductName ProductID="P-5680V-7.3.3">Financial Services Analytical Applications Infrastructure Version 7.3.3</FullProductName>
               </Branch>
               <Branch Name="7.3.4" Type="Product Version">
                  <FullProductName ProductID="P-5680V-7.3.4">Financial Services Analytical Applications Infrastructure Version 7.3.4</FullProductName>
               </Branch>
               <Branch Name="7.3.5" Type="Product Version">
                  <FullProductName ProductID="P-5680V-7.3.5">Financial Services Analytical Applications Infrastructure Version 7.3.5</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Analytical Applications Reconciliation Framework" Type="Product Name">
               <Branch Name="8.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5748V-8.0.0">Financial Services Analytical Applications Reconciliation Framework Version 8.0.0</FullProductName>
               </Branch>
               <Branch Name="8.0.1" Type="Product Version">
                  <FullProductName ProductID="P-5748V-8.0.1">Financial Services Analytical Applications Reconciliation Framework Version 8.0.1</FullProductName>
               </Branch>
               <Branch Name="8.0.2" Type="Product Version">
                  <FullProductName ProductID="P-5748V-8.0.2">Financial Services Analytical Applications Reconciliation Framework Version 8.0.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Pricing Management, Transfer Pricing Component" Type="Product Name">
               <Branch Name="8.0.0 to 8.0.4" Type="Product Version">
                  <FullProductName ProductID="P-5749V-8.0.0 to 8.0.4">Financial Services Pricing Management, Transfer Pricing Component Version 8.0.0 to 8.0.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="FLEXCUBE Universal Banking" Type="Product Name">
               <Branch Name="11.3.0" Type="Product Version">
                  <FullProductName ProductID="P-9052V-11.3.0">FLEXCUBE Universal Banking Version 11.3.0</FullProductName>
               </Branch>
               <Branch Name="11.4.0" Type="Product Version">
                  <FullProductName ProductID="P-9052V-11.4.0">FLEXCUBE Universal Banking Version 11.4.0</FullProductName>
               </Branch>
               <Branch Name="12.0.0" Type="Product Version">
                  <FullProductName ProductID="P-9052V-12.0.0">FLEXCUBE Universal Banking Version 12.0.0</FullProductName>
               </Branch>
               <Branch Name="12.0.1" Type="Product Version">
                  <FullProductName ProductID="P-9052V-12.0.1">FLEXCUBE Universal Banking Version 12.0.1</FullProductName>
               </Branch>
               <Branch Name="12.0.2" Type="Product Version">
                  <FullProductName ProductID="P-9052V-12.0.2">FLEXCUBE Universal Banking Version 12.0.2</FullProductName>
               </Branch>
               <Branch Name="12.0.3" Type="Product Version">
                  <FullProductName ProductID="P-9052V-12.0.3">FLEXCUBE Universal Banking Version 12.0.3</FullProductName>
               </Branch>
               <Branch Name="12.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9052V-12.1.0">FLEXCUBE Universal Banking Version 12.1.0</FullProductName>
               </Branch>
               <Branch Name="12.2.0" Type="Product Version">
                  <FullProductName ProductID="P-9052V-12.2.0">FLEXCUBE Universal Banking Version 12.2.0</FullProductName>
               </Branch>
               <Branch Name="12.3.0" Type="Product Version">
                  <FullProductName ProductID="P-9052V-12.3.0">FLEXCUBE Universal Banking Version 12.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Liquidity Risk Management" Type="Product Name">
               <Branch Name="8.0.1" Type="Product Version">
                  <FullProductName ProductID="P-9096V-8.0.1">Financial Services Liquidity Risk Management Version 8.0.1</FullProductName>
               </Branch>
               <Branch Name="8.0.2" Type="Product Version">
                  <FullProductName ProductID="P-9096V-8.0.2">Financial Services Liquidity Risk Management Version 8.0.2</FullProductName>
               </Branch>
               <Branch Name="8.0.4" Type="Product Version">
                  <FullProductName ProductID="P-9096V-8.0.4">Financial Services Liquidity Risk Management Version 8.0.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="FLEXCUBE Investor Servicing" Type="Product Name">
               <Branch Name="12.0.1" Type="Product Version">
                  <FullProductName ProductID="P-9099V-12.0.1">FLEXCUBE Investor Servicing Version 12.0.1</FullProductName>
               </Branch>
               <Branch Name="12.0.2" Type="Product Version">
                  <FullProductName ProductID="P-9099V-12.0.2">FLEXCUBE Investor Servicing Version 12.0.2</FullProductName>
               </Branch>
               <Branch Name="12.0.3" Type="Product Version">
                  <FullProductName ProductID="P-9099V-12.0.3">FLEXCUBE Investor Servicing Version 12.0.3</FullProductName>
               </Branch>
               <Branch Name="12.0.4" Type="Product Version">
                  <FullProductName ProductID="P-9099V-12.0.4">FLEXCUBE Investor Servicing Version 12.0.4</FullProductName>
               </Branch>
               <Branch Name="12.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9099V-12.1.0">FLEXCUBE Investor Servicing Version 12.1.0</FullProductName>
               </Branch>
               <Branch Name="12.2.0" Type="Product Version">
                  <FullProductName ProductID="P-9099V-12.2.0">FLEXCUBE Investor Servicing Version 12.2.0</FullProductName>
               </Branch>
               <Branch Name="12.3.0" Type="Product Version">
                  <FullProductName ProductID="P-9099V-12.3.0">FLEXCUBE Investor Servicing Version 12.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="FLEXCUBE Enterprise Limits and Collateral Management" Type="Product Name">
               <Branch Name="12.0.0" Type="Product Version">
                  <FullProductName ProductID="P-9100V-12.0.0">FLEXCUBE Enterprise Limits and Collateral Management Version 12.0.0</FullProductName>
               </Branch>
               <Branch Name="12.0.1" Type="Product Version">
                  <FullProductName ProductID="P-9100V-12.0.1">FLEXCUBE Enterprise Limits and Collateral Management Version 12.0.1</FullProductName>
               </Branch>
               <Branch Name="12.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9100V-12.1.0">FLEXCUBE Enterprise Limits and Collateral Management Version 12.1.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="FLEXCUBE Private Banking" Type="Product Name">
               <Branch Name="12.0.0" Type="Product Version">
                  <FullProductName ProductID="P-9110V-12.0.0">FLEXCUBE Private Banking Version 12.0.0</FullProductName>
               </Branch>
               <Branch Name="12.0.1" Type="Product Version">
                  <FullProductName ProductID="P-9110V-12.0.1">FLEXCUBE Private Banking Version 12.0.1</FullProductName>
               </Branch>
               <Branch Name="12.0.2" Type="Product Version">
                  <FullProductName ProductID="P-9110V-12.0.2">FLEXCUBE Private Banking Version 12.0.2</FullProductName>
               </Branch>
               <Branch Name="12.0.3" Type="Product Version">
                  <FullProductName ProductID="P-9110V-12.0.3">FLEXCUBE Private Banking Version 12.0.3</FullProductName>
               </Branch>
               <Branch Name="12.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9110V-12.1.0">FLEXCUBE Private Banking Version 12.1.0</FullProductName>
               </Branch>
               <Branch Name="2.0.0" Type="Product Version">
                  <FullProductName ProductID="P-9110V-2.0.0">FLEXCUBE Private Banking Version 2.0.0</FullProductName>
               </Branch>
               <Branch Name="2.0.1" Type="Product Version">
                  <FullProductName ProductID="P-9110V-2.0.1">FLEXCUBE Private Banking Version 2.0.1</FullProductName>
               </Branch>
               <Branch Name="2.2.0.1" Type="Product Version">
                  <FullProductName ProductID="P-9110V-2.2.0.1">FLEXCUBE Private Banking Version 2.2.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="FLEXCUBE Direct Banking" Type="Product Name">
               <Branch Name="12.0.2" Type="Product Version">
                  <FullProductName ProductID="P-9111V-12.0.2">FLEXCUBE Direct Banking Version 12.0.2</FullProductName>
               </Branch>
               <Branch Name="12.0.3" Type="Product Version">
                  <FullProductName ProductID="P-9111V-12.0.3">FLEXCUBE Direct Banking Version 12.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Data Foundation" Type="Product Name">
               <Branch Name="8.0.1" Type="Product Version">
                  <FullProductName ProductID="P-9180V-8.0.1">Financial Services Data Foundation Version 8.0.1</FullProductName>
               </Branch>
               <Branch Name="8.0.2" Type="Product Version">
                  <FullProductName ProductID="P-9180V-8.0.2">Financial Services Data Foundation Version 8.0.2</FullProductName>
               </Branch>
               <Branch Name="8.0.3" Type="Product Version">
                  <FullProductName ProductID="P-9180V-8.0.3">Financial Services Data Foundation Version 8.0.3</FullProductName>
               </Branch>
               <Branch Name="8.0.4" Type="Product Version">
                  <FullProductName ProductID="P-9180V-8.0.4">Financial Services Data Foundation Version 8.0.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Hedge Management and IFRS Valuations" Type="Product Name">
               <Branch Name="6.1.1" Type="Product Version">
                  <FullProductName ProductID="P-9332V-6.1.1">Financial Services Hedge Management and IFRS Valuations Version 6.1.1</FullProductName>
               </Branch>
               <Branch Name="8.0.1" Type="Product Version">
                  <FullProductName ProductID="P-9332V-8.0.1">Financial Services Hedge Management and IFRS Valuations Version 8.0.1</FullProductName>
               </Branch>
               <Branch Name="8.0.2" Type="Product Version">
                  <FullProductName ProductID="P-9332V-8.0.2">Financial Services Hedge Management and IFRS Valuations Version 8.0.2</FullProductName>
               </Branch>
               <Branch Name="8.0.3" Type="Product Version">
                  <FullProductName ProductID="P-9332V-8.0.3">Financial Services Hedge Management and IFRS Valuations Version 8.0.3</FullProductName>
               </Branch>
               <Branch Name="8.0.4" Type="Product Version">
                  <FullProductName ProductID="P-9332V-8.0.4">Financial Services Hedge Management and IFRS Valuations Version 8.0.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Basel Regulatory Capital Internal Ratings Based Approach" Type="Product Name">
               <Branch Name="6.1.2" Type="Product Version">
                  <FullProductName ProductID="P-9450V-6.1.2">Financial Services Basel Regulatory Capital Internal Ratings Based Approach Version 6.1.2</FullProductName>
               </Branch>
               <Branch Name="6.1.3" Type="Product Version">
                  <FullProductName ProductID="P-9450V-6.1.3">Financial Services Basel Regulatory Capital Internal Ratings Based Approach Version 6.1.3</FullProductName>
               </Branch>
               <Branch Name="8.0.2" Type="Product Version">
                  <FullProductName ProductID="P-9450V-8.0.2">Financial Services Basel Regulatory Capital Internal Ratings Based Approach Version 8.0.2</FullProductName>
               </Branch>
               <Branch Name="8.0.3" Type="Product Version">
                  <FullProductName ProductID="P-9450V-8.0.3">Financial Services Basel Regulatory Capital Internal Ratings Based Approach Version 8.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Loan Loss Forecasting and Provisioning" Type="Product Name">
               <Branch Name="1.5.0" Type="Product Version">
                  <FullProductName ProductID="P-9474V-1.5.0">Financial Services Loan Loss Forecasting and Provisioning Version 1.5.0</FullProductName>
               </Branch>
               <Branch Name="1.5.1" Type="Product Version">
                  <FullProductName ProductID="P-9474V-1.5.1">Financial Services Loan Loss Forecasting and Provisioning Version 1.5.1</FullProductName>
               </Branch>
               <Branch Name="8.0.1" Type="Product Version">
                  <FullProductName ProductID="P-9474V-8.0.1">Financial Services Loan Loss Forecasting and Provisioning Version 8.0.1</FullProductName>
               </Branch>
               <Branch Name="8.0.2" Type="Product Version">
                  <FullProductName ProductID="P-9474V-8.0.2">Financial Services Loan Loss Forecasting and Provisioning Version 8.0.2</FullProductName>
               </Branch>
               <Branch Name="8.0.3" Type="Product Version">
                  <FullProductName ProductID="P-9474V-8.0.3">Financial Services Loan Loss Forecasting and Provisioning Version 8.0.3</FullProductName>
               </Branch>
               <Branch Name="8.0.4" Type="Product Version">
                  <FullProductName ProductID="P-9474V-8.0.4">Financial Services Loan Loss Forecasting and Provisioning Version 8.0.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Basel Regulatory Capital Basic" Type="Product Name">
               <Branch Name="6.1.2" Type="Product Version">
                  <FullProductName ProductID="P-9612V-6.1.2">Financial Services Basel Regulatory Capital Basic Version 6.1.2</FullProductName>
               </Branch>
               <Branch Name="6.1.3" Type="Product Version">
                  <FullProductName ProductID="P-9612V-6.1.3">Financial Services Basel Regulatory Capital Basic Version 6.1.3</FullProductName>
               </Branch>
               <Branch Name="8.0.2" Type="Product Version">
                  <FullProductName ProductID="P-9612V-8.0.2">Financial Services Basel Regulatory Capital Basic Version 8.0.2</FullProductName>
               </Branch>
               <Branch Name="8.0.3" Type="Product Version">
                  <FullProductName ProductID="P-9612V-8.0.3">Financial Services Basel Regulatory Capital Basic Version 8.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Insurance Data Foundation" Type="Product Name">
               <Branch Name="8.0.1" Type="Product Version">
                  <FullProductName ProductID="P-9755V-8.0.1">Insurance Data Foundation Version 8.0.1</FullProductName>
               </Branch>
               <Branch Name="8.0.2" Type="Product Version">
                  <FullProductName ProductID="P-9755V-8.0.2">Insurance Data Foundation Version 8.0.2</FullProductName>
               </Branch>
               <Branch Name="8.0.3" Type="Product Version">
                  <FullProductName ProductID="P-9755V-8.0.3">Insurance Data Foundation Version 8.0.3</FullProductName>
               </Branch>
               <Branch Name="8.0.4" Type="Product Version">
                  <FullProductName ProductID="P-9755V-8.0.4">Insurance Data Foundation Version 8.0.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Retail Customer Analytics" Type="Product Name">
               <Branch Name="8.0.0 to 8.0.3" Type="Product Version">
                  <FullProductName ProductID="P-10214V-8.0.0 to 8.0.3">Financial Services Retail Customer Analytics Version 8.0.0 to 8.0.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Institutional Performance Analytics" Type="Product Name">
               <Branch Name="8.0.0 to 8.0.4" Type="Product Version">
                  <FullProductName ProductID="P-10215V-8.0.0 to 8.0.4">Financial Services Institutional Performance Analytics Version 8.0.0 to 8.0.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Retail Performance Analytics" Type="Product Name">
               <Branch Name="8.0.0 to 8.0.4" Type="Product Version">
                  <FullProductName ProductID="P-10216V-8.0.0 to 8.0.4">Financial Services Retail Performance Analytics Version 8.0.0 to 8.0.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Financial Services Data Integration Hub" Type="Product Name">
               <Branch Name="8.0.1" Type="Product Version">
                  <FullProductName ProductID="P-11289V-8.0.1">Financial Services Data Integration Hub Version 8.0.1</FullProductName>
               </Branch>
               <Branch Name="8.0.2" Type="Product Version">
                  <FullProductName ProductID="P-11289V-8.0.2">Financial Services Data Integration Hub Version 8.0.2</FullProductName>
               </Branch>
               <Branch Name="8.0.3" Type="Product Version">
                  <FullProductName ProductID="P-11289V-8.0.3">Financial Services Data Integration Hub Version 8.0.3</FullProductName>
               </Branch>
               <Branch Name="8.0.4" Type="Product Version">
                  <FullProductName ProductID="P-11289V-8.0.4">Financial Services Data Integration Hub Version 8.0.4</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Fusion Middleware" Type="Product Family">
            <Branch Name="Fusion Middleware MapViewer" Type="Product Name">
               <Branch Name="11.1.1.9" Type="Product Version">
                  <FullProductName ProductID="P-1215V-11.1.1.9">Fusion Middleware MapViewer Version 11.1.1.9</FullProductName>
               </Branch>
               <Branch Name="12.2.1.1" Type="Product Version">
                  <FullProductName ProductID="P-1215V-12.2.1.1">Fusion Middleware MapViewer Version 12.2.1.1</FullProductName>
               </Branch>
               <Branch Name="12.2.1.2" Type="Product Version">
                  <FullProductName ProductID="P-1215V-12.2.1.2">Fusion Middleware MapViewer Version 12.2.1.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Identity Manager" Type="Product Name">
               <Branch Name="11.1.2.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1980V-11.1.2.3.0">Identity Manager Version 11.1.2.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebCenter Content" Type="Product Name">
               <Branch Name="11.1.1.7" Type="Product Version">
                  <FullProductName ProductID="P-2271V-11.1.1.7">WebCenter Content Version 11.1.1.7</FullProductName>
               </Branch>
               <Branch Name="11.1.1.9" Type="Product Version">
                  <FullProductName ProductID="P-2271V-11.1.1.9">WebCenter Content Version 11.1.1.9</FullProductName>
               </Branch>
               <Branch Name="12.2.1.0" Type="Product Version">
                  <FullProductName ProductID="P-2271V-12.2.1.0">WebCenter Content Version 12.2.1.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.1" Type="Product Version">
                  <FullProductName ProductID="P-2271V-12.2.1.1">WebCenter Content Version 12.2.1.1</FullProductName>
               </Branch>
               <Branch Name="12.2.1.2" Type="Product Version">
                  <FullProductName ProductID="P-2271V-12.2.1.2">WebCenter Content Version 12.2.1.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebLogic Server" Type="Product Name">
               <Branch Name="10.3.6.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-10.3.6.0">WebLogic Server Version 10.3.6.0</FullProductName>
               </Branch>
               <Branch Name="12.1.3.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.1.3.0">WebLogic Server Version 12.1.3.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.2.1.0">WebLogic Server Version 12.2.1.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.1" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.2.1.1">WebLogic Server Version 12.2.1.1</FullProductName>
               </Branch>
               <Branch Name="12.2.1.2" Type="Product Version">
                  <FullProductName ProductID="P-5242V-12.2.1.2">WebLogic Server Version 12.2.1.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Service Bus" Type="Product Name">
               <Branch Name="12.1.3.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5308V-12.1.3.0.0">Service Bus Version 12.1.3.0.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.0.0" Type="Product Version">
                  <FullProductName ProductID="P-5308V-12.2.1.0.0">Service Bus Version 12.2.1.0.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.1.0" Type="Product Version">
                  <FullProductName ProductID="P-5308V-12.2.1.1.0">Service Bus Version 12.2.1.1.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.2.0" Type="Product Version">
                  <FullProductName ProductID="P-5308V-12.2.1.2.0">Service Bus Version 12.2.1.2.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="GlassFish Server" Type="Product Name">
               <Branch Name="3.1.2" Type="Product Version">
                  <FullProductName ProductID="P-8493V-3.1.2">GlassFish Server Version 3.1.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="API Gateway" Type="Product Name">
               <Branch Name="11.1.2.4.0" Type="Product Version">
                  <FullProductName ProductID="P-9195V-11.1.2.4.0">API Gateway Version 11.1.2.4.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Social Network" Type="Product Name">
               <Branch Name="prior to 11.1.12.0.0 (17019101)" Type="Product Version">
                  <FullProductName ProductID="P-9432V-prior to 11.1.12.0.0 (17019101)">Social Network Version prior to 11.1.12.0.0 (17019101)</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="WebCenter Sites" Type="Product Name">
               <Branch Name="11.1.1.8.0" Type="Product Version">
                  <FullProductName ProductID="P-9617V-11.1.1.8.0">WebCenter Sites Version 11.1.1.8.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.0.0" Type="Product Version">
                  <FullProductName ProductID="P-9617V-12.2.1.0.0">WebCenter Sites Version 12.2.1.0.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.1.0" Type="Product Version">
                  <FullProductName ProductID="P-9617V-12.2.1.1.0">WebCenter Sites Version 12.2.1.1.0</FullProductName>
               </Branch>
               <Branch Name="12.2.1.2.0" Type="Product Version">
                  <FullProductName ProductID="P-9617V-12.2.1.2.0">WebCenter Sites Version 12.2.1.2.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Health Sciences Applications" Type="Product Family">
            <Branch Name="Healthcare Master Person Index" Type="Product Name">
               <Branch Name="3.0.0.x and 4.0.1.x" Type="Product Version">
                  <FullProductName ProductID="P-8575V-3.0.0.x and 4.0.1.x">Healthcare Master Person Index Version 3.0.0.x and 4.0.1.x</FullProductName>
               </Branch>
               <Branch Name="Prior to and 2.0.1.x" Type="Product Version">
                  <FullProductName ProductID="P-8575V-Prior to and 2.0.1.x">Healthcare Master Person Index Version Prior to and 2.0.1.x</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Hospitality Applications" Type="Product Family">
            <Branch Name="Hospitality OPERA 5 Property Services" Type="Product Name">
               <Branch Name="5.4.0.x" Type="Product Version">
                  <FullProductName ProductID="P-11580V-5.4.0.x">Hospitality OPERA 5 Property Services Version 5.4.0.x</FullProductName>
               </Branch>
               <Branch Name="5.4.1.x" Type="Product Version">
                  <FullProductName ProductID="P-11580V-5.4.1.x">Hospitality OPERA 5 Property Services Version 5.4.1.x</FullProductName>
               </Branch>
               <Branch Name="5.4.2.x" Type="Product Version">
                  <FullProductName ProductID="P-11580V-5.4.2.x">Hospitality OPERA 5 Property Services Version 5.4.2.x</FullProductName>
               </Branch>
               <Branch Name="5.4.3.x" Type="Product Version">
                  <FullProductName ProductID="P-11580V-5.4.3.x">Hospitality OPERA 5 Property Services Version 5.4.3.x</FullProductName>
               </Branch>
               <Branch Name="5.5.0.x" Type="Product Version">
                  <FullProductName ProductID="P-11580V-5.5.0.x">Hospitality OPERA 5 Property Services Version 5.5.0.x</FullProductName>
               </Branch>
               <Branch Name="5.5.1.x" Type="Product Version">
                  <FullProductName ProductID="P-11580V-5.5.1.x">Hospitality OPERA 5 Property Services Version 5.5.1.x</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Hyperion" Type="Product Family">
            <Branch Name="Hyperion Essbase" Type="Product Name">
               <Branch Name="11.1.2.2" Type="Product Version">
                  <FullProductName ProductID="P-4379V-11.1.2.2">Hyperion Essbase Version 11.1.2.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Insurance Applications" Type="Product Family">
            <Branch Name="Insurance Istream" Type="Product Name">
               <Branch Name="4.3.2 and prior" Type="Product Version">
                  <FullProductName ProductID="P-5486V-4.3.2 and prior">Insurance Istream Version 4.3.2 and prior</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle JD Edwards Products" Type="Product Family">
            <Branch Name="JD Edwards EnterpriseOne Tools" Type="Product Name">
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-4781V-9.2">JD Edwards EnterpriseOne Tools Version 9.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Java SE" Type="Product Family">
            <Branch Name="Java" Type="Product Name">
               <Branch Name="7u131" Type="Product Version">
                  <FullProductName ProductID="P-856V-7u131">Java Version 7u131</FullProductName>
               </Branch>
               <Branch Name="8u121" Type="Product Version">
                  <FullProductName ProductID="P-856V-8u121">Java Version 8u121</FullProductName>
               </Branch>
               <Branch Name="8u121; Java SE Embedded: 8u121" Type="Product Version">
                  <FullProductName ProductID="P-856V-8u121; Java SE Embedded: 8u121">Java Version 8u121; Java SE Embedded: 8u121</FullProductName>
               </Branch>
               <Branch Name="8u121; Java SE Embedded: 8u121; JRockit: R28.3.13" Type="Product Version">
                  <FullProductName ProductID="P-856V-8u121; Java SE Embedded: 8u121; JRockit: R28.3.13">Java Version 8u121; Java SE Embedded: 8u121; JRockit: R28.3.13</FullProductName>
               </Branch>
               <Branch Name="Java SE: 6u141" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE: 6u141">Java Version Java SE: 6u141</FullProductName>
               </Branch>
               <Branch Name="Java SE: 7u131" Type="Product Version">
                  <FullProductName ProductID="P-856V-Java SE: 7u131">Java Version Java SE: 7u131</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle MySQL" Type="Product Family">
            <Branch Name="MySQL Workbench" Type="Product Name">
               <Branch Name="6.3.7 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-4627V-6.3.7 and earlier">MySQL Workbench Version 6.3.7 and earlier</FullProductName>
               </Branch>
               <Branch Name="6.3.8 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-4627V-6.3.8 and earlier">MySQL Workbench Version 6.3.8 and earlier</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MySQL Enterprise Backup" Type="Product Name">
               <Branch Name="3.12.2 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-4629V-3.12.2 and earlier">MySQL Enterprise Backup Version 3.12.2 and earlier</FullProductName>
               </Branch>
               <Branch Name="3.12.3 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-4629V-3.12.3 and earlier">MySQL Enterprise Backup Version 3.12.3 and earlier</FullProductName>
               </Branch>
               <Branch Name="4.0.1 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-4629V-4.0.1 and earlier">MySQL Enterprise Backup Version 4.0.1 and earlier</FullProductName>
               </Branch>
               <Branch Name="4.0.3 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-4629V-4.0.3 and earlier">MySQL Enterprise Backup Version 4.0.3 and earlier</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MySQL Server" Type="Product Name">
               <Branch Name="5.5.54 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.5.54 and earlier">MySQL Server Version 5.5.54 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.5.55 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.5.55 and earlier">MySQL Server Version 5.5.55 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.6.20 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.6.20 and earlier">MySQL Server Version 5.6.20 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.6.35 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.6.35 and earlier">MySQL Server Version 5.6.35 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.7.11 to 5.7.17" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.7.11 to 5.7.17">MySQL Server Version 5.7.11 to 5.7.17</FullProductName>
               </Branch>
               <Branch Name="5.7.17 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8478V-5.7.17 and earlier">MySQL Server Version 5.7.17 and earlier</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MySQL Cluster" Type="Product Name">
               <Branch Name="7.2.27 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8479V-7.2.27 and earlier">MySQL Cluster Version 7.2.27 and earlier</FullProductName>
               </Branch>
               <Branch Name="7.3.16 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8479V-7.3.16 and earlier">MySQL Cluster Version 7.3.16 and earlier</FullProductName>
               </Branch>
               <Branch Name="7.4.14 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8479V-7.4.14 and earlier">MySQL Cluster Version 7.4.14 and earlier</FullProductName>
               </Branch>
               <Branch Name="7.5.5 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8479V-7.5.5 and earlier">MySQL Cluster Version 7.5.5 and earlier</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MySQL Enterprise Monitor" Type="Product Name">
               <Branch Name="3.1.6.8003 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8480V-3.1.6.8003 and earlier">MySQL Enterprise Monitor Version 3.1.6.8003 and earlier</FullProductName>
               </Branch>
               <Branch Name="3.2.1182 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8480V-3.2.1182 and earlier">MySQL Enterprise Monitor Version 3.2.1182 and earlier</FullProductName>
               </Branch>
               <Branch Name="3.3.2.1162 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8480V-3.3.2.1162 and earlier">MySQL Enterprise Monitor Version 3.3.2.1162 and earlier</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MySQL Connectors" Type="Product Name">
               <Branch Name="2.1.5 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8576V-2.1.5 and earlier">MySQL Connectors Version 2.1.5 and earlier</FullProductName>
               </Branch>
               <Branch Name="5.1.40 and eariler" Type="Product Version">
                  <FullProductName ProductID="P-8576V-5.1.40 and eariler">MySQL Connectors Version 5.1.40 and eariler</FullProductName>
               </Branch>
               <Branch Name="5.1.41 and earlier" Type="Product Version">
                  <FullProductName ProductID="P-8576V-5.1.41 and earlier">MySQL Connectors Version 5.1.41 and earlier</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle PeopleSoft Products" Type="Product Family">
            <Branch Name="PeopleSoft Enterprise FIN eSettlements" Type="Product Name">
               <Branch Name="9.1" Type="Product Version">
                  <FullProductName ProductID="P-4987V-9.1">PeopleSoft Enterprise FIN eSettlements Version 9.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise FIN Receivables" Type="Product Name">
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-5021V-9.2">PeopleSoft Enterprise FIN Receivables Version 9.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise PT PeopleTools" Type="Product Name">
               <Branch Name="8.54" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.54">PeopleSoft Enterprise PT PeopleTools Version 8.54</FullProductName>
               </Branch>
               <Branch Name="8.55" Type="Product Version">
                  <FullProductName ProductID="P-5085V-8.55">PeopleSoft Enterprise PT PeopleTools Version 8.55</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise SCM eBill Payment" Type="Product Name">
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-5115V-9.2">PeopleSoft Enterprise SCM eBill Payment Version 9.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise SCM eSupplier Connection" Type="Product Name">
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-5122V-9.2">PeopleSoft Enterprise SCM eSupplier Connection Version 9.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise SCM Purchasing" Type="Product Name">
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-5133V-9.2">PeopleSoft Enterprise SCM Purchasing Version 9.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise SCM Services Procurement" Type="Product Name">
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-5135V-9.2">PeopleSoft Enterprise SCM Services Procurement Version 9.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise SCM Strategic Sourcing" Type="Product Name">
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-5136V-9.2">PeopleSoft Enterprise SCM Strategic Sourcing Version 9.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="PeopleSoft Enterprise CS Campus Community" Type="Product Name">
               <Branch Name="9.2" Type="Product Version">
                  <FullProductName ProductID="P-5183V-9.2">PeopleSoft Enterprise CS Campus Community Version 9.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Primavera Products Suite" Type="Product Family">
            <Branch Name="Primavera P6 Enterprise Project Portfolio Management" Type="Product Name">
               <Branch Name="15.1" Type="Product Version">
                  <FullProductName ProductID="P-5579V-15.1">Primavera P6 Enterprise Project Portfolio Management Version 15.1</FullProductName>
               </Branch>
               <Branch Name="15.2" Type="Product Version">
                  <FullProductName ProductID="P-5579V-15.2">Primavera P6 Enterprise Project Portfolio Management Version 15.2</FullProductName>
               </Branch>
               <Branch Name="16.1" Type="Product Version">
                  <FullProductName ProductID="P-5579V-16.1">Primavera P6 Enterprise Project Portfolio Management Version 16.1</FullProductName>
               </Branch>
               <Branch Name="16.2" Type="Product Version">
                  <FullProductName ProductID="P-5579V-16.2">Primavera P6 Enterprise Project Portfolio Management Version 16.2</FullProductName>
               </Branch>
               <Branch Name="8.3" Type="Product Version">
                  <FullProductName ProductID="P-5579V-8.3">Primavera P6 Enterprise Project Portfolio Management Version 8.3</FullProductName>
               </Branch>
               <Branch Name="8.4" Type="Product Version">
                  <FullProductName ProductID="P-5579V-8.4">Primavera P6 Enterprise Project Portfolio Management Version 8.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Primavera P6 Professional Project Management" Type="Product Name">
               <Branch Name="15.1" Type="Product Version">
                  <FullProductName ProductID="P-5580V-15.1">Primavera P6 Professional Project Management Version 15.1</FullProductName>
               </Branch>
               <Branch Name="15.2" Type="Product Version">
                  <FullProductName ProductID="P-5580V-15.2">Primavera P6 Professional Project Management Version 15.2</FullProductName>
               </Branch>
               <Branch Name="16.1" Type="Product Version">
                  <FullProductName ProductID="P-5580V-16.1">Primavera P6 Professional Project Management Version 16.1</FullProductName>
               </Branch>
               <Branch Name="16.2" Type="Product Version">
                  <FullProductName ProductID="P-5580V-16.2">Primavera P6 Professional Project Management Version 16.2</FullProductName>
               </Branch>
               <Branch Name="8.3" Type="Product Version">
                  <FullProductName ProductID="P-5580V-8.3">Primavera P6 Professional Project Management Version 8.3</FullProductName>
               </Branch>
               <Branch Name="8.4" Type="Product Version">
                  <FullProductName ProductID="P-5580V-8.4">Primavera P6 Professional Project Management Version 8.4</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Primavera Unifier" Type="Product Name">
               <Branch Name="10.0" Type="Product Version">
                  <FullProductName ProductID="P-10354V-10.0">Primavera Unifier Version 10.0</FullProductName>
               </Branch>
               <Branch Name="10.1" Type="Product Version">
                  <FullProductName ProductID="P-10354V-10.1">Primavera Unifier Version 10.1</FullProductName>
               </Branch>
               <Branch Name="15.1" Type="Product Version">
                  <FullProductName ProductID="P-10354V-15.1">Primavera Unifier Version 15.1</FullProductName>
               </Branch>
               <Branch Name="15.2" Type="Product Version">
                  <FullProductName ProductID="P-10354V-15.2">Primavera Unifier Version 15.2</FullProductName>
               </Branch>
               <Branch Name="9.13" Type="Product Version">
                  <FullProductName ProductID="P-10354V-9.13">Primavera Unifier Version 9.13</FullProductName>
               </Branch>
               <Branch Name="9.14" Type="Product Version">
                  <FullProductName ProductID="P-10354V-9.14">Primavera Unifier Version 9.14</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Primavera Gateway" Type="Product Name">
               <Branch Name="1.0" Type="Product Version">
                  <FullProductName ProductID="P-10605V-1.0">Primavera Gateway Version 1.0</FullProductName>
               </Branch>
               <Branch Name="1.1" Type="Product Version">
                  <FullProductName ProductID="P-10605V-1.1">Primavera Gateway Version 1.1</FullProductName>
               </Branch>
               <Branch Name="14.2" Type="Product Version">
                  <FullProductName ProductID="P-10605V-14.2">Primavera Gateway Version 14.2</FullProductName>
               </Branch>
               <Branch Name="15.1" Type="Product Version">
                  <FullProductName ProductID="P-10605V-15.1">Primavera Gateway Version 15.1</FullProductName>
               </Branch>
               <Branch Name="15.2" Type="Product Version">
                  <FullProductName ProductID="P-10605V-15.2">Primavera Gateway Version 15.2</FullProductName>
               </Branch>
               <Branch Name="16.1" Type="Product Version">
                  <FullProductName ProductID="P-10605V-16.1">Primavera Gateway Version 16.1</FullProductName>
               </Branch>
               <Branch Name="16.2" Type="Product Version">
                  <FullProductName ProductID="P-10605V-16.2">Primavera Gateway Version 16.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Retail Applications" Type="Product Family">
            <Branch Name="Retail Advanced Inventory Planning" Type="Product Name">
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-1785V-14.1">Retail Advanced Inventory Planning Version 14.1</FullProductName>
               </Branch>
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-1785V-15.0">Retail Advanced Inventory Planning Version 15.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Category Management" Type="Product Name">
               <Branch Name="13.2" Type="Product Version">
                  <FullProductName ProductID="P-1787V-13.2">Retail Category Management Version 13.2</FullProductName>
               </Branch>
               <Branch Name="13.3" Type="Product Version">
                  <FullProductName ProductID="P-1787V-13.3">Retail Category Management Version 13.3</FullProductName>
               </Branch>
               <Branch Name="14.0" Type="Product Version">
                  <FullProductName ProductID="P-1787V-14.0">Retail Category Management Version 14.0</FullProductName>
               </Branch>
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-1787V-14.1">Retail Category Management Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Assortment Planning" Type="Product Name">
               <Branch Name="14.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1788V-14.1.3">Retail Assortment Planning Version 14.1.3</FullProductName>
               </Branch>
               <Branch Name="15.0.1" Type="Product Version">
                  <FullProductName ProductID="P-1788V-15.0.1">Retail Assortment Planning Version 15.0.1</FullProductName>
               </Branch>
               <Branch Name="16.0.0" Type="Product Version">
                  <FullProductName ProductID="P-1788V-16.0.0">Retail Assortment Planning Version 16.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Demand Forecasting" Type="Product Name">
               <Branch Name="14.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1800V-14.1.3">Retail Demand Forecasting Version 14.1.3</FullProductName>
               </Branch>
               <Branch Name="15.0.2" Type="Product Version">
                  <FullProductName ProductID="P-1800V-15.0.2">Retail Demand Forecasting Version 15.0.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Invoice Matching" Type="Product Name">
               <Branch Name="12.0" Type="Product Version">
                  <FullProductName ProductID="P-1810V-12.0">Retail Invoice Matching Version 12.0</FullProductName>
               </Branch>
               <Branch Name="13.0" Type="Product Version">
                  <FullProductName ProductID="P-1810V-13.0">Retail Invoice Matching Version 13.0</FullProductName>
               </Branch>
               <Branch Name="13.1" Type="Product Version">
                  <FullProductName ProductID="P-1810V-13.1">Retail Invoice Matching Version 13.1</FullProductName>
               </Branch>
               <Branch Name="13.2" Type="Product Version">
                  <FullProductName ProductID="P-1810V-13.2">Retail Invoice Matching Version 13.2</FullProductName>
               </Branch>
               <Branch Name="14.0" Type="Product Version">
                  <FullProductName ProductID="P-1810V-14.0">Retail Invoice Matching Version 14.0</FullProductName>
               </Branch>
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-1810V-14.1">Retail Invoice Matching Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Item Planning" Type="Product Name">
               <Branch Name="14.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1811V-14.1.3">Retail Item Planning Version 14.1.3</FullProductName>
               </Branch>
               <Branch Name="15.0.2" Type="Product Version">
                  <FullProductName ProductID="P-1811V-15.0.2">Retail Item Planning Version 15.0.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Merchandise Financial Planning" Type="Product Name">
               <Branch Name="14.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1814V-14.1.3">Retail Merchandise Financial Planning Version 14.1.3</FullProductName>
               </Branch>
               <Branch Name="15.0.2" Type="Product Version">
                  <FullProductName ProductID="P-1814V-15.0.2">Retail Merchandise Financial Planning Version 15.0.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Predictive Application Server" Type="Product Name">
               <Branch Name="13.1" Type="Product Version">
                  <FullProductName ProductID="P-1823V-13.1">Retail Predictive Application Server Version 13.1</FullProductName>
               </Branch>
               <Branch Name="13.2" Type="Product Version">
                  <FullProductName ProductID="P-1823V-13.2">Retail Predictive Application Server Version 13.2</FullProductName>
               </Branch>
               <Branch Name="13.3" Type="Product Version">
                  <FullProductName ProductID="P-1823V-13.3">Retail Predictive Application Server Version 13.3</FullProductName>
               </Branch>
               <Branch Name="13.3.3" Type="Product Version">
                  <FullProductName ProductID="P-1823V-13.3.3">Retail Predictive Application Server Version 13.3.3</FullProductName>
               </Branch>
               <Branch Name="13.4" Type="Product Version">
                  <FullProductName ProductID="P-1823V-13.4">Retail Predictive Application Server Version 13.4</FullProductName>
               </Branch>
               <Branch Name="13.4.3" Type="Product Version">
                  <FullProductName ProductID="P-1823V-13.4.3">Retail Predictive Application Server Version 13.4.3</FullProductName>
               </Branch>
               <Branch Name="14.0" Type="Product Version">
                  <FullProductName ProductID="P-1823V-14.0">Retail Predictive Application Server Version 14.0</FullProductName>
               </Branch>
               <Branch Name="14.0.3" Type="Product Version">
                  <FullProductName ProductID="P-1823V-14.0.3">Retail Predictive Application Server Version 14.0.3</FullProductName>
               </Branch>
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-1823V-14.1">Retail Predictive Application Server Version 14.1</FullProductName>
               </Branch>
               <Branch Name="14.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1823V-14.1.3">Retail Predictive Application Server Version 14.1.3</FullProductName>
               </Branch>
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-1823V-15.0">Retail Predictive Application Server Version 15.0</FullProductName>
               </Branch>
               <Branch Name="15.0.2" Type="Product Version">
                  <FullProductName ProductID="P-1823V-15.0.2">Retail Predictive Application Server Version 15.0.2</FullProductName>
               </Branch>
               <Branch Name="16.0.0" Type="Product Version">
                  <FullProductName ProductID="P-1823V-16.0.0">Retail Predictive Application Server Version 16.0.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Replenishment Optimization" Type="Product Name">
               <Branch Name="14.1.3" Type="Product Version">
                  <FullProductName ProductID="P-1829V-14.1.3">Retail Replenishment Optimization Version 14.1.3</FullProductName>
               </Branch>
               <Branch Name="15.0.2" Type="Product Version">
                  <FullProductName ProductID="P-1829V-15.0.2">Retail Replenishment Optimization Version 15.0.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Store Inventory Management" Type="Product Name">
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-1838V-14.1">Retail Store Inventory Management Version 14.1</FullProductName>
               </Branch>
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-1838V-15.0">Retail Store Inventory Management Version 15.0</FullProductName>
               </Branch>
               <Branch Name="16.0" Type="Product Version">
                  <FullProductName ProductID="P-1838V-16.0">Retail Store Inventory Management Version 16.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Warehouse Management System" Type="Product Name">
               <Branch Name="13.2" Type="Product Version">
                  <FullProductName ProductID="P-1847V-13.2">Retail Warehouse Management System Version 13.2</FullProductName>
               </Branch>
               <Branch Name="14.0" Type="Product Version">
                  <FullProductName ProductID="P-1847V-14.0">Retail Warehouse Management System Version 14.0</FullProductName>
               </Branch>
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-1847V-15.0">Retail Warehouse Management System Version 15.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Back Office" Type="Product Name">
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-2013V-14.1">Retail Back Office Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Point-of-Service" Type="Product Name">
               <Branch Name="14.1.3" Type="Product Version">
                  <FullProductName ProductID="P-2017V-14.1.3">Retail Point-of-Service Version 14.1.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Returns Management" Type="Product Name">
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-2020V-14.1">Retail Returns Management Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Regular Price Optimization" Type="Product Name">
               <Branch Name="14.1.3" Type="Product Version">
                  <FullProductName ProductID="P-4658V-14.1.3">Retail Regular Price Optimization Version 14.1.3</FullProductName>
               </Branch>
               <Branch Name="15.0.2" Type="Product Version">
                  <FullProductName ProductID="P-4658V-15.0.2">Retail Regular Price Optimization Version 15.0.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Size Profile Optimization" Type="Product Name">
               <Branch Name="14.1.3" Type="Product Version">
                  <FullProductName ProductID="P-4670V-14.1.3">Retail Size Profile Optimization Version 14.1.3</FullProductName>
               </Branch>
               <Branch Name="15.0.2" Type="Product Version">
                  <FullProductName ProductID="P-4670V-15.0.2">Retail Size Profile Optimization Version 15.0.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Analytic Parameter Calculator - RO" Type="Product Name">
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-5598V-15.0">Retail Analytic Parameter Calculator - RO Version 15.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Analytics" Type="Product Name">
               <Branch Name="14.0" Type="Product Version">
                  <FullProductName ProductID="P-9346V-14.0">Retail Analytics Version 14.0</FullProductName>
               </Branch>
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-9346V-14.1">Retail Analytics Version 14.1</FullProductName>
               </Branch>
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-9346V-15.0">Retail Analytics Version 15.0</FullProductName>
               </Branch>
               <Branch Name="16.0" Type="Product Version">
                  <FullProductName ProductID="P-9346V-16.0">Retail Analytics Version 16.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Advanced Science Engine" Type="Product Name">
               <Branch Name="14.1" Type="Product Version">
                  <FullProductName ProductID="P-10872V-14.1">Retail Advanced Science Engine Version 14.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="XBRi Cloud Service" Type="Product Name">
               <Branch Name="10.0.1" Type="Product Version">
                  <FullProductName ProductID="P-11506V-10.0.1">XBRi Cloud Service Version 10.0.1</FullProductName>
               </Branch>
               <Branch Name="10.5.0" Type="Product Version">
                  <FullProductName ProductID="P-11506V-10.5.0">XBRi Cloud Service Version 10.5.0</FullProductName>
               </Branch>
               <Branch Name="10.6.0" Type="Product Version">
                  <FullProductName ProductID="P-11506V-10.6.0">XBRi Cloud Service Version 10.6.0</FullProductName>
               </Branch>
               <Branch Name="10.7.0" Type="Product Version">
                  <FullProductName ProductID="P-11506V-10.7.0">XBRi Cloud Service Version 10.7.0</FullProductName>
               </Branch>
               <Branch Name="10.8.0" Type="Product Version">
                  <FullProductName ProductID="P-11506V-10.8.0">XBRi Cloud Service Version 10.8.0</FullProductName>
               </Branch>
               <Branch Name="10.8.1" Type="Product Version">
                  <FullProductName ProductID="P-11506V-10.8.1">XBRi Cloud Service Version 10.8.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Xstore Point of Service" Type="Product Name">
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-11513V-15.0">Retail Xstore Point of Service Version 15.0</FullProductName>
               </Branch>
               <Branch Name="16.0" Type="Product Version">
                  <FullProductName ProductID="P-11513V-16.0">Retail Xstore Point of Service Version 16.0</FullProductName>
               </Branch>
               <Branch Name="5.5" Type="Product Version">
                  <FullProductName ProductID="P-11513V-5.5">Retail Xstore Point of Service Version 5.5</FullProductName>
               </Branch>
               <Branch Name="6.0" Type="Product Version">
                  <FullProductName ProductID="P-11513V-6.0">Retail Xstore Point of Service Version 6.0</FullProductName>
               </Branch>
               <Branch Name="6.5" Type="Product Version">
                  <FullProductName ProductID="P-11513V-6.5">Retail Xstore Point of Service Version 6.5</FullProductName>
               </Branch>
               <Branch Name="7.0" Type="Product Version">
                  <FullProductName ProductID="P-11513V-7.0">Retail Xstore Point of Service Version 7.0</FullProductName>
               </Branch>
               <Branch Name="7.1" Type="Product Version">
                  <FullProductName ProductID="P-11513V-7.1">Retail Xstore Point of Service Version 7.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Customer Management and Segmentation Foundation Cloud Service" Type="Product Name">
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-11518V-15.0">Retail Customer Management and Segmentation Foundation Cloud Service Version 15.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Order Broker Cloud Service" Type="Product Name">
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-11520V-15.0">Retail Order Broker Cloud Service Version 15.0</FullProductName>
               </Branch>
               <Branch Name="16.0" Type="Product Version">
                  <FullProductName ProductID="P-11520V-16.0">Retail Order Broker Cloud Service Version 16.0</FullProductName>
               </Branch>
               <Branch Name="5.1" Type="Product Version">
                  <FullProductName ProductID="P-11520V-5.1">Retail Order Broker Cloud Service Version 5.1</FullProductName>
               </Branch>
               <Branch Name="5.2" Type="Product Version">
                  <FullProductName ProductID="P-11520V-5.2">Retail Order Broker Cloud Service Version 5.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Open Commerce Platform Cloud Service" Type="Product Name">
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-11521V-15.0">Retail Open Commerce Platform Cloud Service Version 15.0</FullProductName>
               </Branch>
               <Branch Name="16.0" Type="Product Version">
                  <FullProductName ProductID="P-11521V-16.0">Retail Open Commerce Platform Cloud Service Version 16.0</FullProductName>
               </Branch>
               <Branch Name="4.0" Type="Product Version">
                  <FullProductName ProductID="P-11521V-4.0">Retail Open Commerce Platform Cloud Service Version 4.0</FullProductName>
               </Branch>
               <Branch Name="5.0" Type="Product Version">
                  <FullProductName ProductID="P-11521V-5.0">Retail Open Commerce Platform Cloud Service Version 5.0</FullProductName>
               </Branch>
               <Branch Name="5.1" Type="Product Version">
                  <FullProductName ProductID="P-11521V-5.1">Retail Open Commerce Platform Cloud Service Version 5.1</FullProductName>
               </Branch>
               <Branch Name="5.3" Type="Product Version">
                  <FullProductName ProductID="P-11521V-5.3">Retail Open Commerce Platform Cloud Service Version 5.3</FullProductName>
               </Branch>
               <Branch Name="6.0" Type="Product Version">
                  <FullProductName ProductID="P-11521V-6.0">Retail Open Commerce Platform Cloud Service Version 6.0</FullProductName>
               </Branch>
               <Branch Name="6.1" Type="Product Version">
                  <FullProductName ProductID="P-11521V-6.1">Retail Open Commerce Platform Cloud Service Version 6.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MICROS Xstore Payment" Type="Product Name">
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-11562V-15.0">MICROS Xstore Payment Version 15.0</FullProductName>
               </Branch>
               <Branch Name="16.0" Type="Product Version">
                  <FullProductName ProductID="P-11562V-16.0">MICROS Xstore Payment Version 16.0</FullProductName>
               </Branch>
               <Branch Name="5.5" Type="Product Version">
                  <FullProductName ProductID="P-11562V-5.5">MICROS Xstore Payment Version 5.5</FullProductName>
               </Branch>
               <Branch Name="6.0" Type="Product Version">
                  <FullProductName ProductID="P-11562V-6.0">MICROS Xstore Payment Version 6.0</FullProductName>
               </Branch>
               <Branch Name="6.5" Type="Product Version">
                  <FullProductName ProductID="P-11562V-6.5">MICROS Xstore Payment Version 6.5</FullProductName>
               </Branch>
               <Branch Name="7.0" Type="Product Version">
                  <FullProductName ProductID="P-11562V-7.0">MICROS Xstore Payment Version 7.0</FullProductName>
               </Branch>
               <Branch Name="7.1" Type="Product Version">
                  <FullProductName ProductID="P-11562V-7.1">MICROS Xstore Payment Version 7.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MICROS XBR" Type="Product Name">
               <Branch Name="10.0.1" Type="Product Version">
                  <FullProductName ProductID="P-11564V-10.0.1">MICROS XBR Version 10.0.1</FullProductName>
               </Branch>
               <Branch Name="10.5.0" Type="Product Version">
                  <FullProductName ProductID="P-11564V-10.5.0">MICROS XBR Version 10.5.0</FullProductName>
               </Branch>
               <Branch Name="10.6.0" Type="Product Version">
                  <FullProductName ProductID="P-11564V-10.6.0">MICROS XBR Version 10.6.0</FullProductName>
               </Branch>
               <Branch Name="10.7.7" Type="Product Version">
                  <FullProductName ProductID="P-11564V-10.7.7">MICROS XBR Version 10.7.7</FullProductName>
               </Branch>
               <Branch Name="10.8.0" Type="Product Version">
                  <FullProductName ProductID="P-11564V-10.8.0">MICROS XBR Version 10.8.0</FullProductName>
               </Branch>
               <Branch Name="10.8.1" Type="Product Version">
                  <FullProductName ProductID="P-11564V-10.8.1">MICROS XBR Version 10.8.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MICROS Relate CRM Software" Type="Product Name">
               <Branch Name="10.0" Type="Product Version">
                  <FullProductName ProductID="P-11566V-10.0">MICROS Relate CRM Software Version 10.0</FullProductName>
               </Branch>
               <Branch Name="10.5" Type="Product Version">
                  <FullProductName ProductID="P-11566V-10.5">MICROS Relate CRM Software Version 10.5</FullProductName>
               </Branch>
               <Branch Name="10.8" Type="Product Version">
                  <FullProductName ProductID="P-11566V-10.8">MICROS Relate CRM Software Version 10.8</FullProductName>
               </Branch>
               <Branch Name="11.0" Type="Product Version">
                  <FullProductName ProductID="P-11566V-11.0">MICROS Relate CRM Software Version 11.0</FullProductName>
               </Branch>
               <Branch Name="11.1" Type="Product Version">
                  <FullProductName ProductID="P-11566V-11.1">MICROS Relate CRM Software Version 11.1</FullProductName>
               </Branch>
               <Branch Name="11.4" Type="Product Version">
                  <FullProductName ProductID="P-11566V-11.4">MICROS Relate CRM Software Version 11.4</FullProductName>
               </Branch>
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-11566V-15.0">MICROS Relate CRM Software Version 15.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Macro Space Optimization" Type="Product Name">
               <Branch Name="15.0.2" Type="Product Version">
                  <FullProductName ProductID="P-12548V-15.0.2">Retail Macro Space Optimization Version 15.0.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Category Management Planning and Optimization" Type="Product Name">
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-12549V-15.0">Retail Category Management Planning and Optimization Version 15.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Merchandising Insights Cloud Service" Type="Product Name">
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-12561V-15.0">Retail Merchandising Insights Cloud Service Version 15.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Retail Customer Insights Cloud Service" Type="Product Name">
               <Branch Name="15.0" Type="Product Version">
                  <FullProductName ProductID="P-12562V-15.0">Retail Customer Insights Cloud Service Version 15.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="MICROS Lucas" Type="Product Name">
               <Branch Name="2.9.5.1" Type="Product Version">
                  <FullProductName ProductID="P-12633V-2.9.5.1">MICROS Lucas Version 2.9.5.1</FullProductName>
               </Branch>
               <Branch Name="2.9.5.2" Type="Product Version">
                  <FullProductName ProductID="P-12633V-2.9.5.2">MICROS Lucas Version 2.9.5.2</FullProductName>
               </Branch>
               <Branch Name="2.9.5.3" Type="Product Version">
                  <FullProductName ProductID="P-12633V-2.9.5.3">MICROS Lucas Version 2.9.5.3</FullProductName>
               </Branch>
               <Branch Name="2.9.5.4" Type="Product Version">
                  <FullProductName ProductID="P-12633V-2.9.5.4">MICROS Lucas Version 2.9.5.4</FullProductName>
               </Branch>
               <Branch Name="2.9.5.5" Type="Product Version">
                  <FullProductName ProductID="P-12633V-2.9.5.5">MICROS Lucas Version 2.9.5.5</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Secure Backup" Type="Product Family">
            <Branch Name="Oracle Secure Backup" Type="Product Name">
               <Branch Name="Prior to 12.1.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1522V-Prior to 12.1.0.3.0">Oracle Secure Backup Version Prior to 12.1.0.3.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Siebel CRM" Type="Product Family">
            <Branch Name="Siebel Apps - E-Billing" Type="Product Name">
               <Branch Name="6.1" Type="Product Version">
                  <FullProductName ProductID="P-8969V-6.1">Siebel Apps - E-Billing Version 6.1</FullProductName>
               </Branch>
               <Branch Name="6.2" Type="Product Version">
                  <FullProductName ProductID="P-8969V-6.2">Siebel Apps - E-Billing Version 6.2</FullProductName>
               </Branch>
               <Branch Name="7.0" Type="Product Version">
                  <FullProductName ProductID="P-8969V-7.0">Siebel Apps - E-Billing Version 7.0</FullProductName>
               </Branch>
               <Branch Name="7.1" Type="Product Version">
                  <FullProductName ProductID="P-8969V-7.1">Siebel Apps - E-Billing Version 7.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Sun Systems Products Suite" Type="Product Family">
            <Branch Name="Solaris Cluster" Type="Product Name">
               <Branch Name="4.3" Type="Product Version">
                  <FullProductName ProductID="P-10005V-4.3">Solaris Cluster Version 4.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Solaris Operating System" Type="Product Name">
               <Branch Name="10" Type="Product Version">
                  <FullProductName ProductID="P-10006V-10">Solaris Operating System Version 10</FullProductName>
               </Branch>
               <Branch Name="11.3" Type="Product Version">
                  <FullProductName ProductID="P-10006V-11.3">Solaris Operating System Version 11.3</FullProductName>
               </Branch>
               <Branch Name="None" Type="Product Version">
                  <FullProductName ProductID="P-10006V-None">Solaris Operating System Version None</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="SuperCluster Specific Software" Type="Product Name">
               <Branch Name="2.3.13" Type="Product Version">
                  <FullProductName ProductID="P-10011V-2.3.13">SuperCluster Specific Software Version 2.3.13</FullProductName>
               </Branch>
               <Branch Name="2.3.8" Type="Product Version">
                  <FullProductName ProductID="P-10011V-2.3.8">SuperCluster Specific Software Version 2.3.8</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Sun ZFS Storage Appliance Kit (AK) Software" Type="Product Name">
               <Branch Name="AK 2013" Type="Product Version">
                  <FullProductName ProductID="P-10026V-AK 2013">Sun ZFS Storage Appliance Kit (AK) Software Version AK 2013</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Tape General STA - StorageTek Tape Analytics SW Tool" Type="Product Name">
               <Branch Name="Prior to 2.2.1" Type="Product Version">
                  <FullProductName ProductID="P-10085V-Prior to 2.2.1">Tape General STA - StorageTek Tape Analytics SW Tool Version Prior to 2.2.1</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Supply Chain Products Suite" Type="Product Family">
            <Branch Name="Transportation Management" Type="Product Name">
               <Branch Name="6.2" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.2">Transportation Management Version 6.2</FullProductName>
               </Branch>
               <Branch Name="6.3.0" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.0">Transportation Management Version 6.3.0</FullProductName>
               </Branch>
               <Branch Name="6.3.1" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.1">Transportation Management Version 6.3.1</FullProductName>
               </Branch>
               <Branch Name="6.3.2" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.2">Transportation Management Version 6.3.2</FullProductName>
               </Branch>
               <Branch Name="6.3.3" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.3">Transportation Management Version 6.3.3</FullProductName>
               </Branch>
               <Branch Name="6.3.4" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.4">Transportation Management Version 6.3.4</FullProductName>
               </Branch>
               <Branch Name="6.3.5" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.5">Transportation Management Version 6.3.5</FullProductName>
               </Branch>
               <Branch Name="6.3.6" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.6">Transportation Management Version 6.3.6</FullProductName>
               </Branch>
               <Branch Name="6.3.7" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.3.7">Transportation Management Version 6.3.7</FullProductName>
               </Branch>
               <Branch Name="6.4.0" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.4.0">Transportation Management Version 6.4.0</FullProductName>
               </Branch>
               <Branch Name="6.4.1" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.4.1">Transportation Management Version 6.4.1</FullProductName>
               </Branch>
               <Branch Name="6.4.2" Type="Product Version">
                  <FullProductName ProductID="P-1991V-6.4.2">Transportation Management Version 6.4.2</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Support Tools" Type="Product Family">
            <Branch Name="OSS Support Tools" Type="Product Name">
               <Branch Name="Prior to RDA 8.15.17.3.14" Type="Product Version">
                  <FullProductName ProductID="P-1330V-Prior to RDA 8.15.17.3.14">OSS Support Tools Version Prior to RDA 8.15.17.3.14</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Automatic Service Request (ASR)" Type="Product Name">
               <Branch Name="Prior to 5.7" Type="Product Version">
                  <FullProductName ProductID="P-9042V-Prior to 5.7">Automatic Service Request (ASR) Version Prior to 5.7</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Advanced Support Gateway" Type="Product Name">
               <Branch Name="Prior to 7.2" Type="Product Version">
                  <FullProductName ProductID="P-9296V-Prior to 7.2">Advanced Support Gateway Version Prior to 7.2</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="System Utilities" Type="Product Name">
               <Branch Name="Prior to 12.1.2.8.4" Type="Product Version">
                  <FullProductName ProductID="P-10655V-Prior to 12.1.2.8.4">System Utilities Version Prior to 12.1.2.8.4</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Utilities Applications" Type="Product Family">
            <Branch Name="Real-Time Scheduler" Type="Product Name">
               <Branch Name="2.2.0.3.13" Type="Product Version">
                  <FullProductName ProductID="P-2238V-2.2.0.3.13">Real-Time Scheduler Version 2.2.0.3.13</FullProductName>
               </Branch>
               <Branch Name="2.3.0.0" Type="Product Version">
                  <FullProductName ProductID="P-2238V-2.3.0.0">Real-Time Scheduler Version 2.3.0.0</FullProductName>
               </Branch>
               <Branch Name="2.3.0.1" Type="Product Version">
                  <FullProductName ProductID="P-2238V-2.3.0.1">Real-Time Scheduler Version 2.3.0.1</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Utilities Work and Asset Management" Type="Product Name">
               <Branch Name="1.9.1.2.11" Type="Product Version">
                  <FullProductName ProductID="P-2244V-1.9.1.2.11">Utilities Work and Asset Management Version 1.9.1.2.11</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Utilities Framework" Type="Product Name">
               <Branch Name="2.2.0.0.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-2.2.0.0.0">Utilities Framework Version 2.2.0.0.0</FullProductName>
               </Branch>
               <Branch Name="4.1.0.1.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.1.0.1.0">Utilities Framework Version 4.1.0.1.0</FullProductName>
               </Branch>
               <Branch Name="4.1.0.2.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.1.0.2.0">Utilities Framework Version 4.1.0.2.0</FullProductName>
               </Branch>
               <Branch Name="4.2.0.1.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.2.0.1.0">Utilities Framework Version 4.2.0.1.0</FullProductName>
               </Branch>
               <Branch Name="4.2.0.2.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.2.0.2.0">Utilities Framework Version 4.2.0.2.0</FullProductName>
               </Branch>
               <Branch Name="4.2.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.2.0.3.0">Utilities Framework Version 4.2.0.3.0</FullProductName>
               </Branch>
               <Branch Name="4.3.0.1.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.3.0.1.0">Utilities Framework Version 4.3.0.1.0</FullProductName>
               </Branch>
               <Branch Name="4.3.0.2.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.3.0.2.0">Utilities Framework Version 4.3.0.2.0</FullProductName>
               </Branch>
               <Branch Name="4.3.0.3.0" Type="Product Version">
                  <FullProductName ProductID="P-2245V-4.3.0.3.0">Utilities Framework Version 4.3.0.3.0</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Utilities Customer Self Service" Type="Product Name">
               <Branch Name="2.1.0.2.0" Type="Product Version">
                  <FullProductName ProductID="P-9426V-2.1.0.2.0">Utilities Customer Self Service Version 2.1.0.2.0</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Virtualization" Type="Product Family">
            <Branch Name="Oracle VM VirtualBox" Type="Product Name">
               <Branch Name="Prior to 5.0.34" Type="Product Version">
                  <FullProductName ProductID="P-8370V-Prior to 5.0.34">Oracle VM VirtualBox Version Prior to 5.0.34</FullProductName>
               </Branch>
               <Branch Name="Prior to 5.0.38" Type="Product Version">
                  <FullProductName ProductID="P-8370V-Prior to 5.0.38">Oracle VM VirtualBox Version Prior to 5.0.38</FullProductName>
               </Branch>
               <Branch Name="Prior to 5.1.16" Type="Product Version">
                  <FullProductName ProductID="P-8370V-Prior to 5.1.16">Oracle VM VirtualBox Version Prior to 5.1.16</FullProductName>
               </Branch>
               <Branch Name="Prior to 5.1.20" Type="Product Version">
                  <FullProductName ProductID="P-8370V-Prior to 5.1.20">Oracle VM VirtualBox Version Prior to 5.1.20</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Secure Global Desktop" Type="Product Name">
               <Branch Name="4.71" Type="Product Version">
                  <FullProductName ProductID="P-8539V-4.71">Secure Global Desktop Version 4.71</FullProductName>
               </Branch>
               <Branch Name="5.2" Type="Product Version">
                  <FullProductName ProductID="P-8539V-5.2">Secure Global Desktop Version 5.2</FullProductName>
               </Branch>
               <Branch Name="5.3" Type="Product Version">
                  <FullProductName ProductID="P-8539V-5.3">Secure Global Desktop Version 5.3</FullProductName>
               </Branch>
            </Branch>
         </Branch>
      </Branch>
   </ProductTree>
   <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2004-2761</Title>
      <Notes>
         <Note Audience="All" Ordinal="1" Title="Details" Type="Details">Vulnerability in the Oracle Trace File Analyzer (TFA) component of Oracle Support Tools (subcomponent: TFA Collector).   The supported version that is affected is Prior to 12.1.2.8.4. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Trace File Analyzer (TFA).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Trace File Analyzer (TFA) accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2004-2761</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10655V-Prior to 12.1.2.8.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10655V-Prior to 12.1.2.8.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-0920</Title>
      <Notes>
         <Note Audience="All" Ordinal="2" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Border Controller component of Oracle Communications Applications (subcomponent: Sysadmin (Dropbear)).  Supported versions that are affected are SCZ7.2.0, SCZ7.3.0 and  SCZ7.4.0. Difficult to exploit vulnerability allows low privileged attacker with network access via SSH to compromise Oracle Communications Session Border Controller.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Communications Session Border Controller. CVSS 3.0 Base Score 7.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-0920</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10750V-SCZ7.2.0</ProductID>
            <ProductID>P-10750V-SCZ7.3.0</ProductID>
            <ProductID>P-10750V-SCZ7.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.1</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10750V-SCZ7.2.0</ProductID>
            <ProductID>P-10750V-SCZ7.3.0</ProductID>
            <ProductID>P-10750V-SCZ7.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2012-5881</Title>
      <Notes>
         <Note Audience="All" Ordinal="3" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Framework component of Oracle Utilities Applications (subcomponent: UI (YUI JavaScript framework)).  Supported versions that are affected are 2.2.0.0.0, 4.1.0.1.0, 4.1.0.2.0, 4.2.0.1.0, 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0, 4.3.0.2.0 and  4.3.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Utilities Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Utilities Framework accessible data as well as  unauthorized read access to a subset of Oracle Utilities Framework accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2012-5881</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2245V-2.2.0.0.0</ProductID>
            <ProductID>P-2245V-4.1.0.1.0</ProductID>
            <ProductID>P-2245V-4.1.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.1.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0</ProductID>
            <ProductID>P-2245V-4.3.0.2.0</ProductID>
            <ProductID>P-2245V-4.3.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2245V-2.2.0.0.0</ProductID>
            <ProductID>P-2245V-4.1.0.1.0</ProductID>
            <ProductID>P-2245V-4.1.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.1.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0</ProductID>
            <ProductID>P-2245V-4.3.0.2.0</ProductID>
            <ProductID>P-2245V-4.3.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-1982</Title>
      <Notes>
         <Note Audience="All" Ordinal="4" Title="Details" Type="Details">Vulnerability in the Secure Global Desktop component of Oracle Virtualization (subcomponent: Window System (X11)).   The supported version that is affected is 4.71. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCP to compromise Secure Global Desktop.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Secure Global Desktop accessible data as well as  unauthorized read access to a subset of Secure Global Desktop accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Secure Global Desktop. CVSS 3.0 Base Score 5.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-1982</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8539V-4.71</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.6</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8539V-4.71</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-2566</Title>
      <Notes>
         <Note Audience="All" Ordinal="5" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Border Controller component of Oracle Communications Applications (subcomponent: Sysadmin).  Supported versions that are affected are SCZ7.3.0 and  SCZ7.4.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSH to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Session Border Controller accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-2566</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10750V-SCZ7.3.0</ProductID>
            <ProductID>P-10750V-SCZ7.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10750V-SCZ7.3.0</ProductID>
            <ProductID>P-10750V-SCZ7.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2013-5209</Title>
      <Notes>
         <Note Audience="All" Ordinal="6" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Border Controller component of Oracle Communications Applications (subcomponent: Sysadmin (SCTP)).  Supported versions that are affected are SCZ7.2.0, SCZ7.3.0 and  SCZ7.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SCTP to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Session Border Controller accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2013-5209</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10750V-SCZ7.2.0</ProductID>
            <ProductID>P-10750V-SCZ7.3.0</ProductID>
            <ProductID>P-10750V-SCZ7.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10750V-SCZ7.2.0</ProductID>
            <ProductID>P-10750V-SCZ7.3.0</ProductID>
            <ProductID>P-10750V-SCZ7.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-0114</Title>
      <Notes>
         <Note Audience="All" Ordinal="7" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Framework component of Oracle Utilities Applications (subcomponent: System Wide).  Supported versions that are affected are 4.1.0.1.0, 4.1.0.2.0, 4.2.0.1.0, 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0, 4.3.0.2.0 and  4.3.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Framework.  While the vulnerability is in Oracle Utilities Framework, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Utilities Framework accessible data as well as  unauthorized read access to a subset of Oracle Utilities Framework accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Utilities Framework. CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-0114</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2245V-4.1.0.1.0</ProductID>
            <ProductID>P-2245V-4.1.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.1.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0</ProductID>
            <ProductID>P-2245V-4.3.0.2.0</ProductID>
            <ProductID>P-2245V-4.3.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2245V-4.1.0.1.0</ProductID>
            <ProductID>P-2245V-4.1.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.1.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0</ProductID>
            <ProductID>P-2245V-4.3.0.2.0</ProductID>
            <ProductID>P-2245V-4.3.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2014-3596</Title>
      <Notes>
         <Note Audience="All" Ordinal="8" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Portal).  Supported versions that are affected are 8.54 and  8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2014-3596</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0204</Title>
      <Notes>
         <Note Audience="All" Ordinal="9" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Border Controller component of Oracle Communications Applications (subcomponent: Routing).  Supported versions that are affected are SCZ7.2.0, SCZ7.3.0 and  SCZ7.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Communications Session Border Controller accessible data. CVSS 3.0 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0204</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10750V-SCZ7.2.0</ProductID>
            <ProductID>P-10750V-SCZ7.3.0</ProductID>
            <ProductID>P-10750V-SCZ7.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10750V-SCZ7.2.0</ProductID>
            <ProductID>P-10750V-SCZ7.3.0</ProductID>
            <ProductID>P-10750V-SCZ7.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-0204</Title>
      <Notes>
         <Note Audience="All" Ordinal="10" Title="Details" Type="Details">Vulnerability in the Oracle Retail Predictive Application Server component of Oracle Retail Applications (subcomponent: RPAS Server).  Supported versions that are affected are 13.3.3, 13.4.3, 14.0.3, 14.1.3, 15.0.2 and 16.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise Oracle Retail Predictive Application Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Retail Predictive Application Server. CVSS 3.0 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-0204</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1823V-13.3.3</ProductID>
            <ProductID>P-1823V-13.4.3</ProductID>
            <ProductID>P-1823V-14.0.3</ProductID>
            <ProductID>P-1823V-14.1.3</ProductID>
            <ProductID>P-1823V-15.0.2</ProductID>
            <ProductID>P-1823V-16.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1823V-13.3.3</ProductID>
            <ProductID>P-1823V-13.4.3</ProductID>
            <ProductID>P-1823V-14.0.3</ProductID>
            <ProductID>P-1823V-14.1.3</ProductID>
            <ProductID>P-1823V-15.0.2</ProductID>
            <ProductID>P-1823V-16.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3237</Title>
      <Notes>
         <Note Audience="All" Ordinal="11" Title="Details" Type="Details">Vulnerability in the Oracle Hyperion Essbase component of Oracle Hyperion (subcomponent: Security (libcurl)).   The supported version that is affected is 11.1.2.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Essbase.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hyperion Essbase accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hyperion Essbase. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3237</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4379V-11.1.2.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-4379V-11.1.2.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-4852</Title>
      <Notes>
         <Note Audience="All" Ordinal="12" Title="Details" Type="Details">Vulnerability in the StorageTek Tape Analytics SW Tool component of Oracle Sun Systems Products Suite (subcomponent: WebLogic Server).   The supported version that is affected is Prior to 2.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3 to compromise StorageTek Tape Analytics SW Tool.  Successful attacks of this vulnerability can result in takeover of StorageTek Tape Analytics SW Tool. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-4852</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10085V-Prior to 2.2.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10085V-Prior to 2.2.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-5252</Title>
      <Notes>
         <Note Audience="All" Ordinal="13" Title="Details" Type="Details">Vulnerability in the Oracle Advanced Support Gateway component of Oracle Support Tools (subcomponent: Samba Service).   The supported version that is affected is Prior to 7.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via SMB to compromise Oracle Advanced Support Gateway.  While the vulnerability is in Oracle Advanced Support Gateway, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Advanced Support Gateway accessible data as well as  unauthorized read access to a subset of Oracle Advanced Support Gateway accessible data. CVSS 3.0 Base Score 7.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-5252</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9296V-Prior to 7.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9296V-Prior to 7.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="14" Title="Details" Type="Details">Vulnerability in the Oracle Fusion Middleware MapViewer component of Oracle Fusion Middleware (subcomponent: Install (Apache Commons Collections)).  Supported versions that are affected are 11.1.1.9, 12.2.1.1 and  12.2.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Fusion Middleware MapViewer.  Successful attacks of this vulnerability can result in takeover of Oracle Fusion Middleware MapViewer. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1215V-11.1.1.9</ProductID>
            <ProductID>P-1215V-12.2.1.1</ProductID>
            <ProductID>P-1215V-12.2.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1215V-11.1.1.9</ProductID>
            <ProductID>P-1215V-12.2.1.1</ProductID>
            <ProductID>P-1215V-12.2.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="15" Title="Details" Type="Details">Vulnerability in the StorageTek Tape Analytics SW Tool component of Oracle Sun Systems Products Suite (subcomponent: Core (Apache Commons Collections)).   The supported version that is affected is Prior to 2.2.1. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise StorageTek Tape Analytics SW Tool.  Successful attacks of this vulnerability can result in takeover of StorageTek Tape Analytics SW Tool. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10085V-Prior to 2.2.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10085V-Prior to 2.2.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7501</Title>
      <Notes>
         <Note Audience="All" Ordinal="16" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Sites (Apache Commons Collections)).  Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and  12.2.1.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="17" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7940</Title>
      <Notes>
         <Note Audience="All" Ordinal="17" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Istream component of Oracle Insurance Applications (subcomponent: IStream Publisher (Bouncy Castle)).  Supported versions that are affected are 4.3.2 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Insurance Istream.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Insurance Istream accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7940</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5486V-4.3.2 and prior</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5486V-4.3.2 and prior</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="18" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-7940</Title>
      <Notes>
         <Note Audience="All" Ordinal="18" Title="Details" Type="Details">Vulnerability in the Oracle Retail Open Commerce Platform component of Oracle Retail Applications (subcomponent: Framework).  Supported versions that are affected are 4.0, 5.0, 5.1, 5.3 and  6.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Open Commerce Platform.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Open Commerce Platform accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-7940</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11521V-4.0</ProductID>
            <ProductID>P-11521V-5.0</ProductID>
            <ProductID>P-11521V-5.1</ProductID>
            <ProductID>P-11521V-5.3</ProductID>
            <ProductID>P-11521V-6.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-11521V-4.0</ProductID>
            <ProductID>P-11521V-5.0</ProductID>
            <ProductID>P-11521V-5.1</ProductID>
            <ProductID>P-11521V-5.3</ProductID>
            <ProductID>P-11521V-6.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="19" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0635</Title>
      <Notes>
         <Note Audience="All" Ordinal="19" Title="Details" Type="Details">Vulnerability in the Oracle Communications Network Integrity component of Oracle Communications Applications (subcomponent: Security (Spring)).  Supported versions that are affected are 7.3.0 and  7.2.4. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Communications Network Integrity.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Network Integrity. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0635</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4491V-7.3.0</ProductID>
            <ProductID>P-4491V-7.2.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-4491V-7.3.0</ProductID>
            <ProductID>P-4491V-7.2.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="20" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0635</Title>
      <Notes>
         <Note Audience="All" Ordinal="20" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Core (Spring Framework)).  Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3 and 12.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.  Successful attacks of this vulnerability can result in takeover of Oracle FLEXCUBE Private Banking. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0635</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-12.0.1</ProductID>
            <ProductID>P-9110V-12.0.2</ProductID>
            <ProductID>P-9110V-12.0.3</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9110V-12.0.1</ProductID>
            <ProductID>P-9110V-12.0.2</ProductID>
            <ProductID>P-9110V-12.0.3</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="21" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0635</Title>
      <Notes>
         <Note Audience="All" Ordinal="21" Title="Details" Type="Details">Vulnerability in the Oracle Retail Back Office component of Oracle Retail Applications (subcomponent: Security).   The supported version that is affected is 14.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Back Office.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Back Office. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0635</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2013V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2013V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="22" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0635</Title>
      <Notes>
         <Note Audience="All" Ordinal="22" Title="Details" Type="Details">Vulnerability in the Oracle Retail Invoice Matching component of Oracle Retail Applications (subcomponent: Security).  Supported versions that are affected are 13.2, 14.0 and  14.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Invoice Matching.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Invoice Matching. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0635</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1810V-13.2</ProductID>
            <ProductID>P-1810V-14.0</ProductID>
            <ProductID>P-1810V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1810V-13.2</ProductID>
            <ProductID>P-1810V-14.0</ProductID>
            <ProductID>P-1810V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="23" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0635</Title>
      <Notes>
         <Note Audience="All" Ordinal="23" Title="Details" Type="Details">Vulnerability in the Oracle Retail Point-of-Service component of Oracle Retail Applications (subcomponent: Mobile POS).   The supported version that is affected is 14.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Point-of-Service.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Point-of-Service. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0635</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2017V-14.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2017V-14.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="24" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0635</Title>
      <Notes>
         <Note Audience="All" Ordinal="24" Title="Details" Type="Details">Vulnerability in the Oracle Retail Returns Management component of Oracle Retail Applications (subcomponent: Security).   The supported version that is affected is 14.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Returns Management.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Returns Management. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0635</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2020V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2020V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="25" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0714</Title>
      <Notes>
         <Note Audience="All" Ordinal="25" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Apache Tomcat).   The supported version that is affected is 11.1.1.8.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0714</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="26" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0729</Title>
      <Notes>
         <Note Audience="All" Ordinal="26" Title="Details" Type="Details">Vulnerability in the Oracle Communications ASAP component of Oracle Communications Applications (subcomponent: Security (Xerces)).  Supported versions that are affected are 7.0, 7.2 and  7.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications ASAP.  Successful attacks of this vulnerability can result in takeover of Oracle Communications ASAP. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0729</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2260V-7.0</ProductID>
            <ProductID>P-2260V-7.2</ProductID>
            <ProductID>P-2260V-7.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2260V-7.0</ProductID>
            <ProductID>P-2260V-7.2</ProductID>
            <ProductID>P-2260V-7.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="27" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-0762</Title>
      <Notes>
         <Note Audience="All" Ordinal="27" Title="Details" Type="Details">Vulnerability in the Secure Global Desktop component of Oracle Virtualization (subcomponent: Application Server (Apache Tomcat)).  Supported versions that are affected are 4.71, 5.2 and  5.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Secure Global Desktop.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Secure Global Desktop accessible data. CVSS 3.0 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-0762</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.2</ProductID>
            <ProductID>P-8539V-5.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.2</ProductID>
            <ProductID>P-8539V-5.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="28" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-1181</Title>
      <Notes>
         <Note Audience="All" Ordinal="28" Title="Details" Type="Details">Vulnerability in the Oracle Retail Invoice Matching component of Oracle Retail Applications (subcomponent: Security).  Supported versions that are affected are 12.0, 13.0, 13.1, 13.2, 14.0 and  14.1. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Retail Invoice Matching executes to compromise Oracle Retail Invoice Matching.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Invoice Matching. CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-1181</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1810V-12.0</ProductID>
            <ProductID>P-1810V-13.0</ProductID>
            <ProductID>P-1810V-13.1</ProductID>
            <ProductID>P-1810V-13.2</ProductID>
            <ProductID>P-1810V-14.0</ProductID>
            <ProductID>P-1810V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1810V-12.0</ProductID>
            <ProductID>P-1810V-13.0</ProductID>
            <ProductID>P-1810V-13.1</ProductID>
            <ProductID>P-1810V-13.2</ProductID>
            <ProductID>P-1810V-14.0</ProductID>
            <ProductID>P-1810V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="29" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-1181</Title>
      <Notes>
         <Note Audience="All" Ordinal="29" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Samples (Struts 1)).  Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and  12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-1181</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.0</ProductID>
            <ProductID>P-5242V-12.2.1.1</ProductID>
            <ProductID>P-5242V-12.2.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.0</ProductID>
            <ProductID>P-5242V-12.2.1.1</ProductID>
            <ProductID>P-5242V-12.2.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="30" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-2107</Title>
      <Notes>
         <Note Audience="All" Ordinal="30" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component of Oracle Commerce (subcomponent: Platform Services).  Supported versions that are affected are 6.1.4, 11.0, 11.1 and  11.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Commerce Guided Search / Oracle Commerce Experience Manager accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-2107</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9633V-6.1.4</ProductID>
            <ProductID>P-9633V-11.0</ProductID>
            <ProductID>P-9633V-11.1</ProductID>
            <ProductID>P-9633V-11.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9633V-6.1.4</ProductID>
            <ProductID>P-9633V-11.0</ProductID>
            <ProductID>P-9633V-11.1</ProductID>
            <ProductID>P-9633V-11.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="31" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-2176</Title>
      <Notes>
         <Note Audience="All" Ordinal="31" Title="Details" Type="Details">Vulnerability in the MySQL Enterprise Backup component of Oracle MySQL (subcomponent: Backup: ENTRBACK (OpenSSL)).  Supported versions that are affected are 3.12.2 and earlier and  
4.0.1 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Backup.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Enterprise Backup and  unauthorized read access to a subset of MySQL Enterprise Backup accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-2176</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4629V-3.12.2 and earlier</ProductID>
            <ProductID>P-4629V-4.0.1 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-4629V-3.12.2 and earlier</ProductID>
            <ProductID>P-4629V-4.0.1 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="32" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-2176</Title>
      <Notes>
         <Note Audience="All" Ordinal="32" Title="Details" Type="Details">Vulnerability in the MySQL Workbench component of Oracle MySQL (subcomponent: Workbench: Security: Encryption (OpenSSL)).  Supported versions that are affected are 6.3.7 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Workbench and  unauthorized read access to a subset of MySQL Workbench accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-2176</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4627V-6.3.7 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-4627V-6.3.7 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="33" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-2510</Title>
      <Notes>
         <Note Audience="All" Ordinal="33" Title="Details" Type="Details">Vulnerability in the Oracle Retail Customer Management and Segmentation Foundation component of Oracle Retail Applications (subcomponent: Web Services).   The supported version that is affected is 15.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Retail Customer Management and Segmentation Foundation.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Customer Management and Segmentation Foundation. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-2510</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11518V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-11518V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="34" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3092</Title>
      <Notes>
         <Note Audience="All" Ordinal="34" Title="Details" Type="Details">Vulnerability in the Oracle Communications Service Broker Engineered System Edition component of Oracle Communications Applications (subcomponent: Install (Apache Commons FileUpload)).  Supported versions that are affected are 6.0 and  6.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Service Broker Engineered System Edition.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Service Broker Engineered System Edition. CVSS 3.0 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3092</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9056V-6.0</ProductID>
            <ProductID>P-9056V-6.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9056V-6.0</ProductID>
            <ProductID>P-9056V-6.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="35" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3092</Title>
      <Notes>
         <Note Audience="All" Ordinal="35" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Security Framework).  Supported versions that are affected are 12.1.0, 
13.1.0 and 
13.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Enterprise Manager Base Platform. CVSS 3.0 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3092</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-12.1.0</ProductID>
            <ProductID>P-1370V-13.1.0</ProductID>
            <ProductID>P-1370V-13.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1370V-12.1.0</ProductID>
            <ProductID>P-1370V-13.1.0</ProductID>
            <ProductID>P-1370V-13.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="36" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3092</Title>
      <Notes>
         <Note Audience="All" Ordinal="36" Title="Details" Type="Details">Vulnerability in the Oracle Healthcare Master Person Index component of Oracle Health Sciences Applications (subcomponent: Cleanser, Profiler (Apache Commons FileUpload)).  Supported versions that are affected are Prior to and 2.0.1.x and  3.0.0.x and 4.0.1.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Healthcare Master Person Index.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Healthcare Master Person Index. CVSS 3.0 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3092</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8575V-Prior to and 2.0.1.x</ProductID>
            <ProductID>P-8575V-3.0.0.x and 4.0.1.x</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8575V-Prior to and 2.0.1.x</ProductID>
            <ProductID>P-8575V-3.0.0.x and 4.0.1.x</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="37" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3092</Title>
      <Notes>
         <Note Audience="All" Ordinal="37" Title="Details" Type="Details">Vulnerability in the MySQL Enterprise Monitor component of Oracle MySQL (subcomponent: Monitoring: General (Apache Commons FileUpload)).  Supported versions that are affected are 3.1.6.8003 and earlier, 
3.2.1182 and earlier and  
3.3.2.1162 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Enterprise Monitor. CVSS 3.0 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3092</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8480V-3.1.6.8003 and earlier</ProductID>
            <ProductID>P-8480V-3.2.1182 and earlier</ProductID>
            <ProductID>P-8480V-3.3.2.1162 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8480V-3.1.6.8003 and earlier</ProductID>
            <ProductID>P-8480V-3.2.1182 and earlier</ProductID>
            <ProductID>P-8480V-3.3.2.1162 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="38" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3092</Title>
      <Notes>
         <Note Audience="All" Ordinal="38" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Framework component of Oracle Utilities Applications (subcomponent: File Uploads and Attachments (Apache Commons FileUpload)).  Supported versions that are affected are 2.2.0.0.0, 4.1.0.1.0, 4.1.0.2.0, 4.2.0.1.0, 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0, 4.3.0.2.0 and  4.3.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Framework.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Framework. CVSS 3.0 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3092</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2245V-2.2.0.0.0</ProductID>
            <ProductID>P-2245V-4.1.0.1.0</ProductID>
            <ProductID>P-2245V-4.1.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.1.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0</ProductID>
            <ProductID>P-2245V-4.3.0.2.0</ProductID>
            <ProductID>P-2245V-4.3.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2245V-2.2.0.0.0</ProductID>
            <ProductID>P-2245V-4.1.0.1.0</ProductID>
            <ProductID>P-2245V-4.1.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.1.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0</ProductID>
            <ProductID>P-2245V-4.3.0.2.0</ProductID>
            <ProductID>P-2245V-4.3.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="39" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3092</Title>
      <Notes>
         <Note Audience="All" Ordinal="39" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Work and Asset Management component of Oracle Utilities Applications (subcomponent: Integrations (Apache Commons FileUpload)).   The supported version that is affected is 1.9.1.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Work and Asset Management.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Utilities Work and Asset Management. CVSS 3.0 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3092</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2244V-1.9.1.2.11</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2244V-1.9.1.2.11</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="40" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="40" Title="Details" Type="Details">Vulnerability in the MICROS Lucas component of Oracle Retail Applications (subcomponent: Security).  Supported versions that are affected are 2.9.5.1, 2.9.5.2, 2.9.5.3,2.9.5.4 and 2.9.5.5. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise MICROS Lucas.  Successful attacks of this vulnerability can result in takeover of MICROS Lucas. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12633V-2.9.5.1</ProductID>
            <ProductID>P-12633V-2.9.5.2</ProductID>
            <ProductID>P-12633V-2.9.5.3</ProductID>
            <ProductID>P-12633V-2.9.5.4</ProductID>
            <ProductID>P-12633V-2.9.5.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-12633V-2.9.5.1</ProductID>
            <ProductID>P-12633V-2.9.5.2</ProductID>
            <ProductID>P-12633V-2.9.5.3</ProductID>
            <ProductID>P-12633V-2.9.5.4</ProductID>
            <ProductID>P-12633V-2.9.5.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="41" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="41" Title="Details" Type="Details">Vulnerability in the MICROS Relate CRM Software component of Oracle Retail Applications (subcomponent: Web Services).  Supported versions that are affected are 10.0, 10.5, 10.8, 11.0, 11.1, 11.4 and  15.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise MICROS Relate CRM Software.  Successful attacks of this vulnerability can result in takeover of MICROS Relate CRM Software. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11566V-10.0</ProductID>
            <ProductID>P-11566V-10.5</ProductID>
            <ProductID>P-11566V-10.8</ProductID>
            <ProductID>P-11566V-11.0</ProductID>
            <ProductID>P-11566V-11.1</ProductID>
            <ProductID>P-11566V-11.4</ProductID>
            <ProductID>P-11566V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-11566V-10.0</ProductID>
            <ProductID>P-11566V-10.5</ProductID>
            <ProductID>P-11566V-10.8</ProductID>
            <ProductID>P-11566V-11.0</ProductID>
            <ProductID>P-11566V-11.1</ProductID>
            <ProductID>P-11566V-11.4</ProductID>
            <ProductID>P-11566V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="42" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="42" Title="Details" Type="Details">Vulnerability in the MICROS XBR component of Oracle Retail Applications (subcomponent: Database).  Supported versions that are affected are 10.0.1, 10.5.0, 10.6.0, 10.7.7, 10.8.0 and  10.8.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise MICROS XBR.  Successful attacks of this vulnerability can result in takeover of MICROS XBR. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11564V-10.0.1</ProductID>
            <ProductID>P-11564V-10.5.0</ProductID>
            <ProductID>P-11564V-10.6.0</ProductID>
            <ProductID>P-11564V-10.7.7</ProductID>
            <ProductID>P-11564V-10.8.0</ProductID>
            <ProductID>P-11564V-10.8.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-11564V-10.0.1</ProductID>
            <ProductID>P-11564V-10.5.0</ProductID>
            <ProductID>P-11564V-10.6.0</ProductID>
            <ProductID>P-11564V-10.7.7</ProductID>
            <ProductID>P-11564V-10.8.0</ProductID>
            <ProductID>P-11564V-10.8.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="43" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="43" Title="Details" Type="Details">Vulnerability in the MICROS Xstore Payment component of Oracle Retail Applications (subcomponent: Security).  Supported versions that are affected are 5.5, 
6.0, 
6.5, 
7.0, 
7.1, 
15.0 and 
16.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise MICROS Xstore Payment.  Successful attacks of this vulnerability can result in takeover of MICROS Xstore Payment. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11562V-5.5</ProductID>
            <ProductID>P-11562V-6.0</ProductID>
            <ProductID>P-11562V-6.5</ProductID>
            <ProductID>P-11562V-7.0</ProductID>
            <ProductID>P-11562V-7.1</ProductID>
            <ProductID>P-11562V-15.0</ProductID>
            <ProductID>P-11562V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-11562V-5.5</ProductID>
            <ProductID>P-11562V-6.0</ProductID>
            <ProductID>P-11562V-6.5</ProductID>
            <ProductID>P-11562V-7.0</ProductID>
            <ProductID>P-11562V-7.1</ProductID>
            <ProductID>P-11562V-15.0</ProductID>
            <ProductID>P-11562V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="44" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="44" Title="Details" Type="Details">Vulnerability in the Oracle Retail Advanced Inventory Planning component of Oracle Retail Applications (subcomponent: Installation).  Supported versions that are affected are 14.1 and  15.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Advanced Inventory Planning.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Advanced Inventory Planning. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1785V-14.1</ProductID>
            <ProductID>P-1785V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1785V-14.1</ProductID>
            <ProductID>P-1785V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="45" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="45" Title="Details" Type="Details">Vulnerability in the Oracle Retail Advanced Science Engine component of Oracle Retail Applications (subcomponent: General).   The supported version that is affected is 14.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Advanced Science Engine.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Advanced Science Engine. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10872V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10872V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="46" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="46" Title="Details" Type="Details">Vulnerability in the Oracle Retail Analytic Parameter Calculator - RO component of Oracle Retail Applications (subcomponent: Installation/Configuration).   The supported version that is affected is 15.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Analytic Parameter Calculator - RO.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Analytic Parameter Calculator - RO. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5598V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5598V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="47" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="47" Title="Details" Type="Details">Vulnerability in the Oracle Retail Analytics component of Oracle Retail Applications (subcomponent: Installation).  Supported versions that are affected are 14.0, 14.1, 15.0 and 16.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Analytics.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Analytics. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9346V-14.0</ProductID>
            <ProductID>P-9346V-14.1</ProductID>
            <ProductID>P-9346V-15.0</ProductID>
            <ProductID>P-9346V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9346V-14.0</ProductID>
            <ProductID>P-9346V-14.1</ProductID>
            <ProductID>P-9346V-15.0</ProductID>
            <ProductID>P-9346V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="48" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="48" Title="Details" Type="Details">Vulnerability in the Oracle Retail Assortment Planning component of Oracle Retail Applications (subcomponent: Installation).  Supported versions that are affected are 14.1.3, 
15.0.1 and 
16.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Assortment Planning.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Assortment Planning. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1788V-14.1.3</ProductID>
            <ProductID>P-1788V-15.0.1</ProductID>
            <ProductID>P-1788V-16.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1788V-14.1.3</ProductID>
            <ProductID>P-1788V-15.0.1</ProductID>
            <ProductID>P-1788V-16.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="49" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="49" Title="Details" Type="Details">Vulnerability in the Oracle Retail Category Management component of Oracle Retail Applications (subcomponent: Installation).  Supported versions that are affected are 13.2, 
13.3, 
14.0 and 
14.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Category Management.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Category Management. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1787V-13.2</ProductID>
            <ProductID>P-1787V-13.3</ProductID>
            <ProductID>P-1787V-14.0</ProductID>
            <ProductID>P-1787V-14.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1787V-13.2</ProductID>
            <ProductID>P-1787V-13.3</ProductID>
            <ProductID>P-1787V-14.0</ProductID>
            <ProductID>P-1787V-14.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="50" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="50" Title="Details" Type="Details">Vulnerability in the Oracle Retail Category Management Planning and Optimization component of Oracle Retail Applications (subcomponent: Installation).   The supported version that is affected is 15.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Category Management Planning and Optimization.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Category Management Planning and Optimization. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12549V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-12549V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="51" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="51" Title="Details" Type="Details">Vulnerability in the Oracle Retail Customer Insights component of Oracle Retail Applications (subcomponent: Installer).   The supported version that is affected is 15.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Customer Insights.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Customer Insights. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12562V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-12562V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="52" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="52" Title="Details" Type="Details">Vulnerability in the Oracle Retail Demand Forecasting component of Oracle Retail Applications (subcomponent: Installation).  Supported versions that are affected are 14.1.3 and 
15.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Demand Forecasting.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Demand Forecasting. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1800V-14.1.3</ProductID>
            <ProductID>P-1800V-15.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1800V-14.1.3</ProductID>
            <ProductID>P-1800V-15.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="53" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="53" Title="Details" Type="Details">Vulnerability in the Oracle Retail Item Planning component of Oracle Retail Applications (subcomponent: Installation).  Supported versions that are affected are 14.1.3 and 
15.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Item Planning.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Item Planning. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1811V-14.1.3</ProductID>
            <ProductID>P-1811V-15.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1811V-14.1.3</ProductID>
            <ProductID>P-1811V-15.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="54" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="54" Title="Details" Type="Details">Vulnerability in the Oracle Retail Macro Space Optimization component of Oracle Retail Applications (subcomponent: Installation).   The supported version that is affected is 15.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Macro Space Optimization.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Macro Space Optimization. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12548V-15.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-12548V-15.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="55" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="55" Title="Details" Type="Details">Vulnerability in the Oracle Retail Merchandise Financial Planning component of Oracle Retail Applications (subcomponent: Installation).  Supported versions that are affected are 14.1.3 and 
15.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Merchandise Financial Planning.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Merchandise Financial Planning. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1814V-14.1.3</ProductID>
            <ProductID>P-1814V-15.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1814V-14.1.3</ProductID>
            <ProductID>P-1814V-15.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="56" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="56" Title="Details" Type="Details">Vulnerability in the Oracle Retail Merchandising Insights component of Oracle Retail Applications (subcomponent: Installer).   The supported version that is affected is 15.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Merchandising Insights.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Merchandising Insights. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-12561V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-12561V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="57" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="57" Title="Details" Type="Details">Vulnerability in the Oracle Retail Order Broker component of Oracle Retail Applications (subcomponent: Order Broker Foundation).  Supported versions that are affected are 5.1, 
5.2, 
15.0 and 
16.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Order Broker.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Order Broker. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11520V-5.1</ProductID>
            <ProductID>P-11520V-5.2</ProductID>
            <ProductID>P-11520V-15.0</ProductID>
            <ProductID>P-11520V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-11520V-5.1</ProductID>
            <ProductID>P-11520V-5.2</ProductID>
            <ProductID>P-11520V-15.0</ProductID>
            <ProductID>P-11520V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="58" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="58" Title="Details" Type="Details">Vulnerability in the Oracle Retail Predictive Application Server component of Oracle Retail Applications (subcomponent: Installer - Server).  Supported versions that are affected are 13.1, 13.2, 13.3, 13.4, 14.0, 14.1 and  15.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Predictive Application Server.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Predictive Application Server. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1823V-13.1</ProductID>
            <ProductID>P-1823V-13.2</ProductID>
            <ProductID>P-1823V-13.3</ProductID>
            <ProductID>P-1823V-13.4</ProductID>
            <ProductID>P-1823V-14.0</ProductID>
            <ProductID>P-1823V-14.1</ProductID>
            <ProductID>P-1823V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1823V-13.1</ProductID>
            <ProductID>P-1823V-13.2</ProductID>
            <ProductID>P-1823V-13.3</ProductID>
            <ProductID>P-1823V-13.4</ProductID>
            <ProductID>P-1823V-14.0</ProductID>
            <ProductID>P-1823V-14.1</ProductID>
            <ProductID>P-1823V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="59" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="59" Title="Details" Type="Details">Vulnerability in the Oracle Retail Regular Price Optimization component of Oracle Retail Applications (subcomponent: Installation).  Supported versions that are affected are 14.1.3 and 
15.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Regular Price Optimization.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Regular Price Optimization. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4658V-14.1.3</ProductID>
            <ProductID>P-4658V-15.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-4658V-14.1.3</ProductID>
            <ProductID>P-4658V-15.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="60" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="60" Title="Details" Type="Details">Vulnerability in the Oracle Retail Replenishment Optimization component of Oracle Retail Applications (subcomponent: Installation).  Supported versions that are affected are 14.1.3 and 
15.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Replenishment Optimization.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Replenishment Optimization. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1829V-14.1.3</ProductID>
            <ProductID>P-1829V-15.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1829V-14.1.3</ProductID>
            <ProductID>P-1829V-15.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="61" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="61" Title="Details" Type="Details">Vulnerability in the Oracle Retail Size Profile Optimization component of Oracle Retail Applications (subcomponent: Installation).  Supported versions that are affected are 14.1.3 and 
15.0.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Size Profile Optimization.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Size Profile Optimization. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4670V-14.1.3</ProductID>
            <ProductID>P-4670V-15.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-4670V-14.1.3</ProductID>
            <ProductID>P-4670V-15.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="62" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="62" Title="Details" Type="Details">Vulnerability in the Oracle Retail Store Inventory component of Oracle Retail Applications (subcomponent: Installation).  Supported versions that are affected are 14.1, 15.0 and  16.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Store Inventory.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Store Inventory. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1838V-14.1</ProductID>
            <ProductID>P-1838V-15.0</ProductID>
            <ProductID>P-1838V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1838V-14.1</ProductID>
            <ProductID>P-1838V-15.0</ProductID>
            <ProductID>P-1838V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="63" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="63" Title="Details" Type="Details">Vulnerability in the Oracle Retail Xstore Point of Service component of Oracle Retail Applications (subcomponent: Point of Sale).  Supported versions that are affected are 5.5, 
6.0, 
6.5, 
7.0, 
7.1, 
15.0 and 
16.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Retail Xstore Point of Service.  Successful attacks of this vulnerability can result in takeover of Oracle Retail Xstore Point of Service. CVSS 3.0 Base Score 8.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11513V-5.5</ProductID>
            <ProductID>P-11513V-6.0</ProductID>
            <ProductID>P-11513V-6.5</ProductID>
            <ProductID>P-11513V-7.0</ProductID>
            <ProductID>P-11513V-7.1</ProductID>
            <ProductID>P-11513V-15.0</ProductID>
            <ProductID>P-11513V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-11513V-5.5</ProductID>
            <ProductID>P-11513V-6.0</ProductID>
            <ProductID>P-11513V-6.5</ProductID>
            <ProductID>P-11513V-7.0</ProductID>
            <ProductID>P-11513V-7.1</ProductID>
            <ProductID>P-11513V-15.0</ProductID>
            <ProductID>P-11513V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="64" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3607</Title>
      <Notes>
         <Note Audience="All" Ordinal="64" Title="Details" Type="Details">Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: GlassFish Server).   The supported version that is affected is 4.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris Cluster.  Successful attacks of this vulnerability can result in takeover of Solaris Cluster. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3607</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10005V-4.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10005V-4.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="65" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3674</Title>
      <Notes>
         <Note Audience="All" Ordinal="65" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Framework component of Oracle Utilities Applications (subcomponent: UI, Batch and XAI (Xstream)).  Supported versions that are affected are 2.2.0.0.0, 4.1.0.1.0, 4.1.0.2.0, 4.2.0.1.0, 4.2.0.2.0, 4.2.0.3.0, 4.3.0.1.0, 4.3.0.2.0 and  4.3.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Framework.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Utilities Framework accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3674</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2245V-2.2.0.0.0</ProductID>
            <ProductID>P-2245V-4.1.0.1.0</ProductID>
            <ProductID>P-2245V-4.1.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.1.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0</ProductID>
            <ProductID>P-2245V-4.3.0.2.0</ProductID>
            <ProductID>P-2245V-4.3.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2245V-2.2.0.0.0</ProductID>
            <ProductID>P-2245V-4.1.0.1.0</ProductID>
            <ProductID>P-2245V-4.1.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.1.0</ProductID>
            <ProductID>P-2245V-4.2.0.2.0</ProductID>
            <ProductID>P-2245V-4.2.0.3.0</ProductID>
            <ProductID>P-2245V-4.3.0.1.0</ProductID>
            <ProductID>P-2245V-4.3.0.2.0</ProductID>
            <ProductID>P-2245V-4.3.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="66" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-3739</Title>
      <Notes>
         <Note Audience="All" Ordinal="66" Title="Details" Type="Details">Vulnerability in the Secure Global Desktop component of Oracle Virtualization (subcomponent: Core (LibcURL)).  Supported versions that are affected are 5.2 and  5.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Secure Global Desktop.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Secure Global Desktop accessible data as well as  unauthorized read access to a subset of Secure Global Desktop accessible data. CVSS 3.0 Base Score 4.8 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-3739</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8539V-5.2</ProductID>
            <ProductID>P-8539V-5.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.8</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8539V-5.2</ProductID>
            <ProductID>P-8539V-5.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="67" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5019</Title>
      <Notes>
         <Note Audience="All" Ordinal="67" Title="Details" Type="Details">Vulnerability in the StorageTek Tape Analytics SW Tool component of Oracle Sun Systems Products Suite (subcomponent: Core (Apache Trinidad)).   The supported version that is affected is Prior to 2.2.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise StorageTek Tape Analytics SW Tool.  Successful attacks of this vulnerability can result in takeover of StorageTek Tape Analytics SW Tool. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5019</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10085V-Prior to 2.2.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10085V-Prior to 2.2.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="68" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5019</Title>
      <Notes>
         <Note Audience="All" Ordinal="68" Title="Details" Type="Details">Vulnerability in the Oracle Utilities Customer Self Service component of Oracle Utilities Applications (subcomponent: Packaging (Apache Trinidad)).   The supported version that is affected is 2.1.0.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Utilities Customer Self Service.  Successful attacks of this vulnerability can result in takeover of Oracle Utilities Customer Self Service. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5019</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9426V-2.1.0.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9426V-2.1.0.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="69" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5407</Title>
      <Notes>
         <Note Audience="All" Ordinal="69" Title="Details" Type="Details">Vulnerability in the Secure Global Desktop component of Oracle Virtualization (subcomponent: Window System (X11)).  Supported versions that are affected are 4.71, 5.2 and  5.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Secure Global Desktop.  Successful attacks of this vulnerability can result in takeover of Secure Global Desktop. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5407</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.2</ProductID>
            <ProductID>P-8539V-5.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.2</ProductID>
            <ProductID>P-8539V-5.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="70" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-5551</Title>
      <Notes>
         <Note Audience="All" Ordinal="70" Title="Details" Type="Details">Vulnerability in the Solaris Cluster component of Oracle Sun Systems Products Suite (subcomponent: NAS device addition).   The supported version that is affected is 4.3. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Solaris Cluster executes to compromise Solaris Cluster.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Solaris Cluster accessible data. CVSS 3.0 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-5551</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10005V-4.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.3</BaseScore>
            <Vector>AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10005V-4.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="71" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-6290</Title>
      <Notes>
         <Note Audience="All" Ordinal="71" Title="Details" Type="Details">Vulnerability in the PHP component of Oracle Secure Backup.   The supported version that is affected is Prior to 12.1.0.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise PHP.  Successful attacks of this vulnerability can result in takeover of PHP. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-6290</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1522V-Prior to 12.1.0.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1522V-Prior to 12.1.0.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="72" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-6303</Title>
      <Notes>
         <Note Audience="All" Ordinal="72" Title="Details" Type="Details">Vulnerability in the Oracle API Gateway component of Oracle Fusion Middleware (subcomponent: Oracle API Gateway (OpenSSL)).   The supported version that is affected is 11.1.2.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle API Gateway.  Successful attacks of this vulnerability can result in takeover of Oracle API Gateway. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-6303</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9195V-11.1.2.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9195V-11.1.2.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="73" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-6303</Title>
      <Notes>
         <Note Audience="All" Ordinal="73" Title="Details" Type="Details">Vulnerability in the MySQL Workbench component of Oracle MySQL (subcomponent: Workbench: Security: Encryption (OpenSSL)).  Supported versions that are affected are 6.3.8 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in takeover of MySQL Workbench. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-6303</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4627V-6.3.8 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-4627V-6.3.8 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="74" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-6304</Title>
      <Notes>
         <Note Audience="All" Ordinal="74" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component of Oracle Commerce (subcomponent: MDEX).  Supported versions that are affected are 6.2.2, 6.3.0, 6.4.1.2, 6.5.0, 6.5.1 and  6.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.0 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-6304</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9633V-6.2.2</ProductID>
            <ProductID>P-9633V-6.3.0</ProductID>
            <ProductID>P-9633V-6.4.1.2</ProductID>
            <ProductID>P-9633V-6.5.0</ProductID>
            <ProductID>P-9633V-6.5.1</ProductID>
            <ProductID>P-9633V-6.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9633V-6.2.2</ProductID>
            <ProductID>P-9633V-6.3.0</ProductID>
            <ProductID>P-9633V-6.4.1.2</ProductID>
            <ProductID>P-9633V-6.5.0</ProductID>
            <ProductID>P-9633V-6.5.1</ProductID>
            <ProductID>P-9633V-6.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="75" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-6304</Title>
      <Notes>
         <Note Audience="All" Ordinal="75" Title="Details" Type="Details">Vulnerability in the Oracle Communications Session Border Controller component of Oracle Communications Applications (subcomponent: Routing (OpenSSL)).  Supported versions that are affected are SCZ7.2.0, SCZ7.3.0 and  SCZ7.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Communications Session Border Controller.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Communications Session Border Controller. CVSS 3.0 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-6304</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10750V-SCZ7.2.0</ProductID>
            <ProductID>P-10750V-SCZ7.3.0</ProductID>
            <ProductID>P-10750V-SCZ7.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10750V-SCZ7.2.0</ProductID>
            <ProductID>P-10750V-SCZ7.3.0</ProductID>
            <ProductID>P-10750V-SCZ7.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="76" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-6304</Title>
      <Notes>
         <Note Audience="All" Ordinal="76" Title="Details" Type="Details">Vulnerability in the OSS Support Tools component of Oracle Support Tools (subcomponent: Oracle Explorer (OpenSSL)).   The supported version that is affected is Prior to RDA 8.15.17.3.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise OSS Support Tools.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of OSS Support Tools. CVSS 3.0 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-6304</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1330V-Prior to RDA 8.15.17.3.14</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1330V-Prior to RDA 8.15.17.3.14</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="77" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2016-8743</Title>
      <Notes>
         <Note Audience="All" Ordinal="77" Title="Details" Type="Details">Vulnerability in the Secure Global Desktop component of Oracle Virtualization (subcomponent: Web Server (Apache HTTP Server)).  Supported versions that are affected are 4.71, 5.2 and  5.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Secure Global Desktop.  While the vulnerability is in Secure Global Desktop, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Secure Global Desktop accessible data. CVSS 3.0 Base Score 4.0 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2016-8743</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.2</ProductID>
            <ProductID>P-8539V-5.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.0</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.2</ProductID>
            <ProductID>P-8539V-5.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="78" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3230</Title>
      <Notes>
         <Note Audience="All" Ordinal="78" Title="Details" Type="Details">Vulnerability in the Oracle Fusion Middleware MapViewer component of Oracle Fusion Middleware (subcomponent: Map Builder).  Supported versions that are affected are 11.1.1.9, 12.2.1.1 and  12.2.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Fusion Middleware MapViewer.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Fusion Middleware MapViewer accessible data as well as  unauthorized read access to a subset of Oracle Fusion Middleware MapViewer accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Fusion Middleware MapViewer. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3230</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1215V-11.1.1.9</ProductID>
            <ProductID>P-1215V-12.2.1.1</ProductID>
            <ProductID>P-1215V-12.2.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1215V-11.1.1.9</ProductID>
            <ProductID>P-1215V-12.2.1.1</ProductID>
            <ProductID>P-1215V-12.2.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="79" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3232</Title>
      <Notes>
         <Note Audience="All" Ordinal="79" Title="Details" Type="Details">Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager).   The supported version that is affected is Prior to 5.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Automatic Service Request (ASR) executes to compromise Automatic Service Request (ASR).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Automatic Service Request (ASR) accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3232</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="80" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3233</Title>
      <Notes>
         <Note Audience="All" Ordinal="80" Title="Details" Type="Details">Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager).   The supported version that is affected is Prior to 5.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Automatic Service Request (ASR).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Automatic Service Request (ASR) accessible data. CVSS 3.0 Base Score 7.5 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3233</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="81" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3234</Title>
      <Notes>
         <Note Audience="All" Ordinal="81" Title="Details" Type="Details">Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager).   The supported version that is affected is Prior to 5.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via SFT to compromise Automatic Service Request (ASR).  Successful attacks of this vulnerability can result in takeover of Automatic Service Request (ASR). CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3234</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="82" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3237</Title>
      <Notes>
         <Note Audience="All" Ordinal="82" Title="Details" Type="Details">Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager).   The supported version that is affected is Prior to 5.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Automatic Service Request (ASR) executes to compromise Automatic Service Request (ASR).  Successful attacks of this vulnerability can result in takeover of Automatic Service Request (ASR). CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3237</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="83" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3254</Title>
      <Notes>
         <Note Audience="All" Ordinal="83" Title="Details" Type="Details">Vulnerability in the Oracle Retail Invoice Matching component of Oracle Retail Applications (subcomponent: Security).  Supported versions that are affected are 12.0 and 13.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Invoice Matching.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Retail Invoice Matching accessible data as well as  unauthorized update, insert or delete access to some of Oracle Retail Invoice Matching accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Retail Invoice Matching. CVSS 3.0 Base Score 7.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3254</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1810V-12.0</ProductID>
            <ProductID>P-1810V-13.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1810V-12.0</ProductID>
            <ProductID>P-1810V-13.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="84" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3288</Title>
      <Notes>
         <Note Audience="All" Ordinal="84" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Unit Trust).  Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle FLEXCUBE Investor Servicing accessible data as well as  unauthorized read access to a subset of Oracle FLEXCUBE Investor Servicing accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3288</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9099V-12.0.1</ProductID>
            <ProductID>P-9099V-12.0.2</ProductID>
            <ProductID>P-9099V-12.0.3</ProductID>
            <ProductID>P-9099V-12.0.4</ProductID>
            <ProductID>P-9099V-12.1.0</ProductID>
            <ProductID>P-9099V-12.2.0</ProductID>
            <ProductID>P-9099V-12.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9099V-12.0.1</ProductID>
            <ProductID>P-9099V-12.0.2</ProductID>
            <ProductID>P-9099V-12.0.3</ProductID>
            <ProductID>P-9099V-12.0.4</ProductID>
            <ProductID>P-9099V-12.1.0</ProductID>
            <ProductID>P-9099V-12.2.0</ProductID>
            <ProductID>P-9099V-12.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="85" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3302</Title>
      <Notes>
         <Note Audience="All" Ordinal="85" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API).  Supported versions that are affected are 5.5.54 and earlier and  5.6.20 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 5.1 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3302</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.20 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.1</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.20 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="86" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3304</Title>
      <Notes>
         <Note Audience="All" Ordinal="86" Title="Details" Type="Details">Vulnerability in the MySQL Cluster component of Oracle MySQL (subcomponent: Cluster: DD).  Supported versions that are affected are 7.2.27 and earlier, 
7.3.16 and earlier, 
7.4.14 and earlier and 
7.5.5 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Cluster.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.0 Base Score 5.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3304</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8479V-7.2.27 and earlier</ProductID>
            <ProductID>P-8479V-7.3.16 and earlier</ProductID>
            <ProductID>P-8479V-7.4.14 and earlier</ProductID>
            <ProductID>P-8479V-7.5.5 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8479V-7.2.27 and earlier</ProductID>
            <ProductID>P-8479V-7.3.16 and earlier</ProductID>
            <ProductID>P-8479V-7.4.14 and earlier</ProductID>
            <ProductID>P-8479V-7.5.5 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="87" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3305</Title>
      <Notes>
         <Note Audience="All" Ordinal="87" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API).  Supported versions that are affected are 5.5.55 and earlier and  5.6.35 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3305</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.55 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.5.55 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="88" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3306</Title>
      <Notes>
         <Note Audience="All" Ordinal="88" Title="Details" Type="Details">Vulnerability in the MySQL Enterprise Monitor component of Oracle MySQL (subcomponent: Monitoring: Server).  Supported versions that are affected are 3.1.6.8003 and earlier, 
3.2.1182 and earlier and  
3.3.2.1162 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MySQL Enterprise Monitor, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all MySQL Enterprise Monitor accessible data as well as  unauthorized access to critical data or complete access to all MySQL Enterprise Monitor accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Enterprise Monitor. CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3306</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8480V-3.1.6.8003 and earlier</ProductID>
            <ProductID>P-8480V-3.2.1182 and earlier</ProductID>
            <ProductID>P-8480V-3.3.2.1162 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8480V-3.1.6.8003 and earlier</ProductID>
            <ProductID>P-8480V-3.2.1182 and earlier</ProductID>
            <ProductID>P-8480V-3.3.2.1162 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="89" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3307</Title>
      <Notes>
         <Note Audience="All" Ordinal="89" Title="Details" Type="Details">Vulnerability in the MySQL Enterprise Monitor component of Oracle MySQL (subcomponent: Monitoring: Server).  Supported versions that are affected are 3.1.6.8003 and earlier, 
3.2.1182 and earlier and  
3.3.2.1162 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Enterprise Monitor accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Enterprise Monitor. CVSS 3.0 Base Score 3.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3307</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8480V-3.1.6.8003 and earlier</ProductID>
            <ProductID>P-8480V-3.2.1182 and earlier</ProductID>
            <ProductID>P-8480V-3.3.2.1162 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8480V-3.1.6.8003 and earlier</ProductID>
            <ProductID>P-8480V-3.2.1182 and earlier</ProductID>
            <ProductID>P-8480V-3.3.2.1162 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="90" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3308</Title>
      <Notes>
         <Note Audience="All" Ordinal="90" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML).  Supported versions that are affected are 5.5.54 and earlier, 
5.6.35 and earlier and  
5.7.17 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  While the vulnerability is in MySQL Server, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.7 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3308</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.7</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="91" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3309</Title>
      <Notes>
         <Note Audience="All" Ordinal="91" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).  Supported versions that are affected are 5.5.54 and earlier, 
5.6.35 and earlier and  
5.7.17 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  While the vulnerability is in MySQL Server, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.7 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3309</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.7</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="92" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3329</Title>
      <Notes>
         <Note Audience="All" Ordinal="92" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Thread Pooling).  Supported versions that are affected are 5.5.54 and earlier, 
5.6.35 and earlier and  
5.7.17 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3329</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="93" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3331</Title>
      <Notes>
         <Note Audience="All" Ordinal="93" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML).   The supported version that is affected is 5.7.11 to 5.7.17. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3331</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.11 to 5.7.17</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.7.11 to 5.7.17</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="94" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3337</Title>
      <Notes>
         <Note Audience="All" Ordinal="94" Title="Details" Type="Details">Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: User Interface).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and  12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Marketing, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Marketing accessible data as well as  unauthorized update, insert or delete access to some of Oracle Marketing accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3337</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-229V-12.1.1</ProductID>
            <ProductID>P-229V-12.1.2</ProductID>
            <ProductID>P-229V-12.1.3</ProductID>
            <ProductID>P-229V-12.2.3</ProductID>
            <ProductID>P-229V-12.2.4</ProductID>
            <ProductID>P-229V-12.2.5</ProductID>
            <ProductID>P-229V-12.2.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-229V-12.1.1</ProductID>
            <ProductID>P-229V-12.1.2</ProductID>
            <ProductID>P-229V-12.1.3</ProductID>
            <ProductID>P-229V-12.2.3</ProductID>
            <ProductID>P-229V-12.2.4</ProductID>
            <ProductID>P-229V-12.2.5</ProductID>
            <ProductID>P-229V-12.2.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="95" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3393</Title>
      <Notes>
         <Note Audience="All" Ordinal="95" Title="Details" Type="Details">Vulnerability in the Oracle Advanced Outbound Telephony component of Oracle E-Business Suite (subcomponent: Interaction History).  Supported versions that are affected are 12.2.3, 12.2.4, 12.2.5 and  12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessible data as well as  unauthorized update, insert or delete access to some of Oracle Advanced Outbound Telephony accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3393</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-785V-12.2.3</ProductID>
            <ProductID>P-785V-12.2.4</ProductID>
            <ProductID>P-785V-12.2.5</ProductID>
            <ProductID>P-785V-12.2.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-785V-12.2.3</ProductID>
            <ProductID>P-785V-12.2.4</ProductID>
            <ProductID>P-785V-12.2.5</ProductID>
            <ProductID>P-785V-12.2.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="96" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3432</Title>
      <Notes>
         <Note Audience="All" Ordinal="96" Title="Details" Type="Details">Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Audience workbench).  Supported versions that are affected are 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data as well as  unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3432</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1379V-12.1.1</ProductID>
            <ProductID>P-1379V-12.1.2</ProductID>
            <ProductID>P-1379V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1379V-12.1.1</ProductID>
            <ProductID>P-1379V-12.1.2</ProductID>
            <ProductID>P-1379V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="97" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3450</Title>
      <Notes>
         <Note Audience="All" Ordinal="97" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Memcached).  Supported versions that are affected are 5.6.35 and earlier and  5.7.17 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3450</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="98" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3451</Title>
      <Notes>
         <Note Audience="All" Ordinal="98" Title="Details" Type="Details">Vulnerability in the Oracle Retail Open Commerce Platform component of Oracle Retail Applications (subcomponent: Web).  Supported versions that are affected are 4.0, 5.0, 5.1, 5.3, 6.0,6.1, 15.0 and 16.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Retail Open Commerce Platform.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Open Commerce Platform, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail Open Commerce Platform accessible data as well as  unauthorized read access to a subset of Oracle Retail Open Commerce Platform accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3451</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11521V-4.0</ProductID>
            <ProductID>P-11521V-5.0</ProductID>
            <ProductID>P-11521V-5.1</ProductID>
            <ProductID>P-11521V-5.3</ProductID>
            <ProductID>P-11521V-6.0</ProductID>
            <ProductID>P-11521V-6.1</ProductID>
            <ProductID>P-11521V-15.0</ProductID>
            <ProductID>P-11521V-16.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-11521V-4.0</ProductID>
            <ProductID>P-11521V-5.0</ProductID>
            <ProductID>P-11521V-5.1</ProductID>
            <ProductID>P-11521V-5.3</ProductID>
            <ProductID>P-11521V-6.0</ProductID>
            <ProductID>P-11521V-6.1</ProductID>
            <ProductID>P-11521V-15.0</ProductID>
            <ProductID>P-11521V-16.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="99" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3452</Title>
      <Notes>
         <Note Audience="All" Ordinal="99" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).  Supported versions that are affected are 5.6.35 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3452</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="100" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3453</Title>
      <Notes>
         <Note Audience="All" Ordinal="100" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).  Supported versions that are affected are 5.5.54 and earlier, 
5.6.35 and earlier and  
5.7.17 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3453</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="101" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3454</Title>
      <Notes>
         <Note Audience="All" Ordinal="101" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: InnoDB).  Supported versions that are affected are 5.7.17 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 5.5 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3454</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="102" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3455</Title>
      <Notes>
         <Note Audience="All" Ordinal="102" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges).  Supported versions that are affected are 5.7.17 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data as well as  unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3455</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="103" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3456</Title>
      <Notes>
         <Note Audience="All" Ordinal="103" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML).  Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and  5.7.17 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3456</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="104" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3457</Title>
      <Notes>
         <Note Audience="All" Ordinal="104" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML).  Supported versions that are affected are 5.7.17 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3457</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="105" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3458</Title>
      <Notes>
         <Note Audience="All" Ordinal="105" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DML).  Supported versions that are affected are 5.7.17 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3458</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="106" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3459</Title>
      <Notes>
         <Note Audience="All" Ordinal="106" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer).  Supported versions that are affected are 5.7.17 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3459</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="107" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3460</Title>
      <Notes>
         <Note Audience="All" Ordinal="107" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Audit Plug-in).  Supported versions that are affected are 5.7.17 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3460</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="108" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3461</Title>
      <Notes>
         <Note Audience="All" Ordinal="108" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges).  Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and  5.7.17 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3461</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="109" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3462</Title>
      <Notes>
         <Note Audience="All" Ordinal="109" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges).  Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and  5.7.17 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3462</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="110" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3463</Title>
      <Notes>
         <Note Audience="All" Ordinal="110" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges).  Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and  5.7.17 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.9 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3463</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.9</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="111" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3464</Title>
      <Notes>
         <Note Audience="All" Ordinal="111" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: DDL).  Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and  5.7.17 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3464</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="112" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3465</Title>
      <Notes>
         <Note Audience="All" Ordinal="112" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges).  Supported versions that are affected are 5.7.17 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3465</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="113" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3467</Title>
      <Notes>
         <Note Audience="All" Ordinal="113" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: C API).  Supported versions that are affected are 5.7.17 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.0 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3467</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="114" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3468</Title>
      <Notes>
         <Note Audience="All" Ordinal="114" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Encryption).  Supported versions that are affected are 5.7.17 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3468</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="115" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3469</Title>
      <Notes>
         <Note Audience="All" Ordinal="115" Title="Details" Type="Details">Vulnerability in the MySQL Workbench component of Oracle MySQL (subcomponent: Workbench: Security : Encryption).  Supported versions that are affected are 6.3.8 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Workbench.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of MySQL Workbench accessible data. CVSS 3.0 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3469</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4627V-6.3.8 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-4627V-6.3.8 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="116" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3470</Title>
      <Notes>
         <Note Audience="All" Ordinal="116" Title="Details" Type="Details">Vulnerability in the Oracle Communications Security Gateway component of Oracle Communications Applications (subcomponent: Network).   The supported version that is affected is 3.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via ICMP Ping to compromise Oracle Communications Security Gateway.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Security Gateway. CVSS 3.0 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3470</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10755V-3.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10755V-3.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="117" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3471</Title>
      <Notes>
         <Note Audience="All" Ordinal="117" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous).  Supported versions that are affected are 12.0.0 and 12.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Private Banking, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle FLEXCUBE Private Banking accessible data. CVSS 3.0 Base Score 4.7 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3471</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="118" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3472</Title>
      <Notes>
         <Note Audience="All" Ordinal="118" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Portfolio Management).  Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0.1 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle FLEXCUBE Private Banking accessible data as well as  unauthorized access to critical data or complete access to all Oracle FLEXCUBE Private Banking accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3472</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-2.0.0</ProductID>
            <ProductID>P-9110V-2.0.1</ProductID>
            <ProductID>P-9110V-2.2.0.1</ProductID>
            <ProductID>P-9110V-12.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9110V-2.0.0</ProductID>
            <ProductID>P-9110V-2.0.1</ProductID>
            <ProductID>P-9110V-2.2.0.1</ProductID>
            <ProductID>P-9110V-12.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="119" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3473</Title>
      <Notes>
         <Note Audience="All" Ordinal="119" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous).  Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0.1 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle FLEXCUBE Private Banking accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3473</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-2.0.0</ProductID>
            <ProductID>P-9110V-2.0.1</ProductID>
            <ProductID>P-9110V-2.2.0.1</ProductID>
            <ProductID>P-9110V-12.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9110V-2.0.0</ProductID>
            <ProductID>P-9110V-2.0.1</ProductID>
            <ProductID>P-9110V-2.2.0.1</ProductID>
            <ProductID>P-9110V-12.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="120" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3474</Title>
      <Notes>
         <Note Audience="All" Ordinal="120" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Zone).   The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Solaris accessible data. CVSS 3.0 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3474</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.3</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10006V-11.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="121" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3475</Title>
      <Notes>
         <Note Audience="All" Ordinal="121" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous).  Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0.1 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.  While the vulnerability is in Oracle FLEXCUBE Private Banking, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle FLEXCUBE Private Banking. CVSS 3.0 Base Score 5.0 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3475</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-2.0.0</ProductID>
            <ProductID>P-9110V-2.0.1</ProductID>
            <ProductID>P-9110V-2.2.0.1</ProductID>
            <ProductID>P-9110V-12.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.0</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9110V-2.0.0</ProductID>
            <ProductID>P-9110V-2.0.1</ProductID>
            <ProductID>P-9110V-2.2.0.1</ProductID>
            <ProductID>P-9110V-12.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="122" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3476</Title>
      <Notes>
         <Note Audience="All" Ordinal="122" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous).  Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0.1 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle FLEXCUBE Private Banking accessible data as well as  unauthorized update, insert or delete access to some of Oracle FLEXCUBE Private Banking accessible data. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3476</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-2.0.0</ProductID>
            <ProductID>P-9110V-2.0.1</ProductID>
            <ProductID>P-9110V-2.2.0.1</ProductID>
            <ProductID>P-9110V-12.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9110V-2.0.0</ProductID>
            <ProductID>P-9110V-2.0.1</ProductID>
            <ProductID>P-9110V-2.2.0.1</ProductID>
            <ProductID>P-9110V-12.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="123" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3477</Title>
      <Notes>
         <Note Audience="All" Ordinal="123" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous).  Supported versions that are affected are 12.0.0 and 12.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle FLEXCUBE Private Banking accessible data as well as  unauthorized read access to a subset of Oracle FLEXCUBE Private Banking accessible data. CVSS 3.0 Base Score 4.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3477</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.2</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="124" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3478</Title>
      <Notes>
         <Note Audience="All" Ordinal="124" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous).  Supported versions that are affected are 12.0.0 and 12.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle FLEXCUBE Private Banking accessible data as well as  unauthorized read access to a subset of Oracle FLEXCUBE Private Banking accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3478</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9110V-12.0.0</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="125" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3479</Title>
      <Notes>
         <Note Audience="All" Ordinal="125" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous).  Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0.1 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle FLEXCUBE Private Banking accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle FLEXCUBE Private Banking. CVSS 3.0 Base Score 5.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3479</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-2.0.0</ProductID>
            <ProductID>P-9110V-2.0.1</ProductID>
            <ProductID>P-9110V-2.2.0.1</ProductID>
            <ProductID>P-9110V-12.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9110V-2.0.0</ProductID>
            <ProductID>P-9110V-2.0.1</ProductID>
            <ProductID>P-9110V-2.2.0.1</ProductID>
            <ProductID>P-9110V-12.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="126" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3480</Title>
      <Notes>
         <Note Audience="All" Ordinal="126" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure).  Supported versions that are affected are 11.3.0, 11.4.0 and 12.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Universal Banking, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.0 Base Score 4.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3480</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-11.3.0</ProductID>
            <ProductID>P-9052V-11.4.0</ProductID>
            <ProductID>P-9052V-12.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9052V-11.3.0</ProductID>
            <ProductID>P-9052V-11.4.0</ProductID>
            <ProductID>P-9052V-12.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="127" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3481</Title>
      <Notes>
         <Note Audience="All" Ordinal="127" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure).  Supported versions that are affected are 11.3.0, 11.4.0 and 12.0.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking.  Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle FLEXCUBE Universal Banking. CVSS 3.0 Base Score 4.3 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3481</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-11.3.0</ProductID>
            <ProductID>P-9052V-11.4.0</ProductID>
            <ProductID>P-9052V-12.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9052V-11.3.0</ProductID>
            <ProductID>P-9052V-11.4.0</ProductID>
            <ProductID>P-9052V-12.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="128" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3482</Title>
      <Notes>
         <Note Audience="All" Ordinal="128" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure).  Supported versions that are affected are 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Universal Banking, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle FLEXCUBE Universal Banking accessible data as well as  unauthorized read access to a subset of Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3482</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-12.0.0</ProductID>
            <ProductID>P-9052V-12.0.1</ProductID>
            <ProductID>P-9052V-12.0.2</ProductID>
            <ProductID>P-9052V-12.0.3</ProductID>
            <ProductID>P-9052V-12.1.0</ProductID>
            <ProductID>P-9052V-12.2.0</ProductID>
            <ProductID>P-9052V-12.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9052V-12.0.0</ProductID>
            <ProductID>P-9052V-12.0.1</ProductID>
            <ProductID>P-9052V-12.0.2</ProductID>
            <ProductID>P-9052V-12.0.3</ProductID>
            <ProductID>P-9052V-12.1.0</ProductID>
            <ProductID>P-9052V-12.2.0</ProductID>
            <ProductID>P-9052V-12.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="129" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3483</Title>
      <Notes>
         <Note Audience="All" Ordinal="129" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Limits and Collateral).  Supported versions that are affected are 12.0.0 and 12.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle FLEXCUBE Enterprise Limits and Collateral Management executes to compromise Oracle FLEXCUBE Enterprise Limits and Collateral Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle FLEXCUBE Enterprise Limits and Collateral Management accessible data. CVSS 3.0 Base Score 4.4 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3483</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9100V-12.0.0</ProductID>
            <ProductID>P-9100V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.4</BaseScore>
            <Vector>AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9100V-12.0.0</ProductID>
            <ProductID>P-9100V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="130" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3484</Title>
      <Notes>
         <Note Audience="All" Ordinal="130" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Limits and Collateral).  Supported versions that are affected are 12.0.0 and 12.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Enterprise Limits and Collateral Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle FLEXCUBE Enterprise Limits and Collateral Management accessible data as well as  unauthorized read access to a subset of Oracle FLEXCUBE Enterprise Limits and Collateral Management accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3484</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9100V-12.0.0</ProductID>
            <ProductID>P-9100V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9100V-12.0.0</ProductID>
            <ProductID>P-9100V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="131" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3485</Title>
      <Notes>
         <Note Audience="All" Ordinal="131" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure).  Supported versions that are affected are 11.3.0, 11.4.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and  12.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle FLEXCUBE Universal Banking accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle FLEXCUBE Universal Banking. CVSS 3.0 Base Score 6.8 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3485</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-11.3.0</ProductID>
            <ProductID>P-9052V-11.4.0</ProductID>
            <ProductID>P-9052V-12.0.0</ProductID>
            <ProductID>P-9052V-12.0.1</ProductID>
            <ProductID>P-9052V-12.0.2</ProductID>
            <ProductID>P-9052V-12.0.3</ProductID>
            <ProductID>P-9052V-12.1.0</ProductID>
            <ProductID>P-9052V-12.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.8</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9052V-11.3.0</ProductID>
            <ProductID>P-9052V-11.4.0</ProductID>
            <ProductID>P-9052V-12.0.0</ProductID>
            <ProductID>P-9052V-12.0.1</ProductID>
            <ProductID>P-9052V-12.0.2</ProductID>
            <ProductID>P-9052V-12.0.3</ProductID>
            <ProductID>P-9052V-12.1.0</ProductID>
            <ProductID>P-9052V-12.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="132" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3486</Title>
      <Notes>
         <Note Audience="All" Ordinal="132" Title="Details" Type="Details">Vulnerability in the SQL*Plus component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4 and  12.1.0.2. Difficult to exploit vulnerability allows high privileged attacker having Local Logon privilege with logon to the infrastructure where SQL*Plus executes to compromise SQL*Plus.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in SQL*Plus, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of SQL*Plus.  Note: This score is for Windows platform version 11.2.0.4 of Database. For Windows platform version 12.1.0.2 and Linux, the score is 6.3 with scope Unchanged. CVSS 3.0 Base Score 7.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3486</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-50V-11.2.0.4</ProductID>
            <ProductID>P-50V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.2</BaseScore>
            <Vector>AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-50V-11.2.0.4</ProductID>
            <ProductID>P-50V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="133" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3487</Title>
      <Notes>
         <Note Audience="All" Ordinal="133" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Unit Trust).  Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0 and 12.3.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle FLEXCUBE Investor Servicing accessible data. CVSS 3.0 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3487</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9099V-12.0.1</ProductID>
            <ProductID>P-9099V-12.0.2</ProductID>
            <ProductID>P-9099V-12.0.3</ProductID>
            <ProductID>P-9099V-12.0.4</ProductID>
            <ProductID>P-9099V-12.1.0</ProductID>
            <ProductID>P-9099V-12.2.0</ProductID>
            <ProductID>P-9099V-12.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9099V-12.0.1</ProductID>
            <ProductID>P-9099V-12.0.2</ProductID>
            <ProductID>P-9099V-12.0.3</ProductID>
            <ProductID>P-9099V-12.0.4</ProductID>
            <ProductID>P-9099V-12.1.0</ProductID>
            <ProductID>P-9099V-12.2.0</ProductID>
            <ProductID>P-9099V-12.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="134" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3488</Title>
      <Notes>
         <Note Audience="All" Ordinal="134" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Unit Trust).  Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle FLEXCUBE Investor Servicing accessible data. CVSS 3.0 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3488</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9099V-12.0.1</ProductID>
            <ProductID>P-9099V-12.0.2</ProductID>
            <ProductID>P-9099V-12.0.3</ProductID>
            <ProductID>P-9099V-12.0.4</ProductID>
            <ProductID>P-9099V-12.1.0</ProductID>
            <ProductID>P-9099V-12.2.0</ProductID>
            <ProductID>P-9099V-12.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9099V-12.0.1</ProductID>
            <ProductID>P-9099V-12.0.2</ProductID>
            <ProductID>P-9099V-12.0.3</ProductID>
            <ProductID>P-9099V-12.0.4</ProductID>
            <ProductID>P-9099V-12.1.0</ProductID>
            <ProductID>P-9099V-12.2.0</ProductID>
            <ProductID>P-9099V-12.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="135" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3489</Title>
      <Notes>
         <Note Audience="All" Ordinal="135" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Security Management System).  Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.0.4, 12.1.0, 12.2.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Investor Servicing.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle FLEXCUBE Investor Servicing accessible data as well as  unauthorized read access to a subset of Oracle FLEXCUBE Investor Servicing accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3489</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9099V-12.0.1</ProductID>
            <ProductID>P-9099V-12.0.2</ProductID>
            <ProductID>P-9099V-12.0.3</ProductID>
            <ProductID>P-9099V-12.0.4</ProductID>
            <ProductID>P-9099V-12.1.0</ProductID>
            <ProductID>P-9099V-12.2.0</ProductID>
            <ProductID>P-9099V-12.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9099V-12.0.1</ProductID>
            <ProductID>P-9099V-12.0.2</ProductID>
            <ProductID>P-9099V-12.0.3</ProductID>
            <ProductID>P-9099V-12.0.4</ProductID>
            <ProductID>P-9099V-12.1.0</ProductID>
            <ProductID>P-9099V-12.2.0</ProductID>
            <ProductID>P-9099V-12.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="136" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3490</Title>
      <Notes>
         <Note Audience="All" Ordinal="136" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Limits and Collateral).  Supported versions that are affected are 12.0.0 and 12.1.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Enterprise Limits and Collateral Management.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle FLEXCUBE Enterprise Limits and Collateral Management accessible data. CVSS 3.0 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3490</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9100V-12.0.0</ProductID>
            <ProductID>P-9100V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9100V-12.0.0</ProductID>
            <ProductID>P-9100V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="137" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3491</Title>
      <Notes>
         <Note Audience="All" Ordinal="137" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Limits and Collateral).  Supported versions that are affected are 12.0.1 and  12.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Enterprise Limits and Collateral Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle FLEXCUBE Enterprise Limits and Collateral Management accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3491</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9100V-12.0.1</ProductID>
            <ProductID>P-9100V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9100V-12.0.1</ProductID>
            <ProductID>P-9100V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="138" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3492</Title>
      <Notes>
         <Note Audience="All" Ordinal="138" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Infrastructure).  Supported versions that are affected are 12.0.0 and 12.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Enterprise Limits and Collateral Management.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle FLEXCUBE Enterprise Limits and Collateral Management accessible data as well as  unauthorized read access to a subset of Oracle FLEXCUBE Enterprise Limits and Collateral Management accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3492</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9100V-12.0.0</ProductID>
            <ProductID>P-9100V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9100V-12.0.0</ProductID>
            <ProductID>P-9100V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="139" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3493</Title>
      <Notes>
         <Note Audience="All" Ordinal="139" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Infrastructure).  Supported versions that are affected are 12.0.0 and 12.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Enterprise Limits and Collateral Management.  While the vulnerability is in Oracle FLEXCUBE Enterprise Limits and Collateral Management, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle FLEXCUBE Enterprise Limits and Collateral Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle FLEXCUBE Enterprise Limits and Collateral Management. CVSS 3.0 Base Score 8.5 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3493</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9100V-12.0.0</ProductID>
            <ProductID>P-9100V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9100V-12.0.0</ProductID>
            <ProductID>P-9100V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="140" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3494</Title>
      <Notes>
         <Note Audience="All" Ordinal="140" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Retail Teller).  Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2 and 12.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Universal Banking, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.0 Base Score 4.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3494</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-11.3.0</ProductID>
            <ProductID>P-9052V-11.4.0</ProductID>
            <ProductID>P-9052V-12.0.1</ProductID>
            <ProductID>P-9052V-12.0.2</ProductID>
            <ProductID>P-9052V-12.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9052V-11.3.0</ProductID>
            <ProductID>P-9052V-11.4.0</ProductID>
            <ProductID>P-9052V-12.0.1</ProductID>
            <ProductID>P-9052V-12.0.2</ProductID>
            <ProductID>P-9052V-12.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="141" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3495</Title>
      <Notes>
         <Note Audience="All" Ordinal="141" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Applications (subcomponent: Pre-Login).  Supported versions that are affected are 12.0.2 and  12.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Direct Banking.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Direct Banking, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle FLEXCUBE Direct Banking accessible data. CVSS 3.0 Base Score 4.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3495</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9111V-12.0.2</ProductID>
            <ProductID>P-9111V-12.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9111V-12.0.2</ProductID>
            <ProductID>P-9111V-12.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="142" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3496</Title>
      <Notes>
         <Note Audience="All" Ordinal="142" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Infrastructure).  Supported versions that are affected are 12.0.0 and 12.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Enterprise Limits and Collateral Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Enterprise Limits and Collateral Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle FLEXCUBE Enterprise Limits and Collateral Management accessible data as well as  unauthorized read access to a subset of Oracle FLEXCUBE Enterprise Limits and Collateral Management accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3496</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9100V-12.0.0</ProductID>
            <ProductID>P-9100V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9100V-12.0.0</ProductID>
            <ProductID>P-9100V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="143" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3497</Title>
      <Notes>
         <Note Audience="All" Ordinal="143" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Remote Administration Daemon).   The supported version that is affected is 11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Solaris accessible data as well as  unauthorized read access to a subset of Solaris accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Solaris. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3497</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10006V-11.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="144" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3498</Title>
      <Notes>
         <Note Audience="All" Ordinal="144" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel).   The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Solaris accessible data. CVSS 3.0 Base Score 3.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3498</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.3</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10006V-11.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="145" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3499</Title>
      <Notes>
         <Note Audience="All" Ordinal="145" Title="Details" Type="Details">Vulnerability in the Oracle Social Network component of Oracle Fusion Middleware (subcomponent: Android Client).   The supported version that is affected is prior to 11.1.12.0.0 (17019101). Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Social Network.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Social Network accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3499</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9432V-prior to 11.1.12.0.0 (17019101)</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9432V-prior to 11.1.12.0.0 (17019101)</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="146" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3500</Title>
      <Notes>
         <Note Audience="All" Ordinal="146" Title="Details" Type="Details">Vulnerability in the Primavera Gateway component of Oracle Primavera Products Suite (subcomponent: Primavera Desktop Integration).  Supported versions that are affected are 1.0, 1.1, 14.2, 15.1, 15.2, 16.1 and  16.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Primavera Gateway.  While the vulnerability is in Primavera Gateway, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Primavera Gateway accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Primavera Gateway. CVSS 3.0 Base Score 8.7 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3500</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10605V-1.0</ProductID>
            <ProductID>P-10605V-1.1</ProductID>
            <ProductID>P-10605V-14.2</ProductID>
            <ProductID>P-10605V-15.1</ProductID>
            <ProductID>P-10605V-15.2</ProductID>
            <ProductID>P-10605V-16.1</ProductID>
            <ProductID>P-10605V-16.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.7</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10605V-1.0</ProductID>
            <ProductID>P-10605V-1.1</ProductID>
            <ProductID>P-10605V-14.2</ProductID>
            <ProductID>P-10605V-15.1</ProductID>
            <ProductID>P-10605V-15.2</ProductID>
            <ProductID>P-10605V-16.1</ProductID>
            <ProductID>P-10605V-16.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="147" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3501</Title>
      <Notes>
         <Note Audience="All" Ordinal="147" Title="Details" Type="Details">Vulnerability in the Primavera Unifier component of Oracle Primavera Products Suite (subcomponent: Platform).  Supported versions that are affected are 9.13, 9.14, 10.0, 10.1, 15.1 and  15.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera Unifier.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera Unifier, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera Unifier accessible data as well as  unauthorized read access to a subset of Primavera Unifier accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3501</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10354V-9.13</ProductID>
            <ProductID>P-10354V-9.14</ProductID>
            <ProductID>P-10354V-10.0</ProductID>
            <ProductID>P-10354V-10.1</ProductID>
            <ProductID>P-10354V-15.1</ProductID>
            <ProductID>P-10354V-15.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10354V-9.13</ProductID>
            <ProductID>P-10354V-9.14</ProductID>
            <ProductID>P-10354V-10.0</ProductID>
            <ProductID>P-10354V-10.1</ProductID>
            <ProductID>P-10354V-15.1</ProductID>
            <ProductID>P-10354V-15.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="148" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3502</Title>
      <Notes>
         <Note Audience="All" Ordinal="148" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise FIN Receivables component of Oracle PeopleSoft Products (subcomponent: Receivables).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise FIN Receivables.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise FIN Receivables accessible data. CVSS 3.0 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3502</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5021V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5021V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="149" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3503</Title>
      <Notes>
         <Note Audience="All" Ordinal="149" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access (Apache Commons BeanUtils)).  Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and  16.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  While the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Primavera P6 Enterprise Project Portfolio Management. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3503</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
            <ProductID>P-5579V-16.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.9</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
            <ProductID>P-5579V-16.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="150" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3504</Title>
      <Notes>
         <Note Audience="All" Ordinal="150" Title="Details" Type="Details">Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager).   The supported version that is affected is Prior to 5.7. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Automatic Service Request (ASR) executes to compromise Automatic Service Request (ASR).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Automatic Service Request (ASR) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Automatic Service Request (ASR). CVSS 3.0 Base Score 5.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3504</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.1</BaseScore>
            <Vector>AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="151" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3505</Title>
      <Notes>
         <Note Audience="All" Ordinal="151" Title="Details" Type="Details">Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager).   The supported version that is affected is Prior to 5.7. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Automatic Service Request (ASR) executes to compromise Automatic Service Request (ASR).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Automatic Service Request (ASR) accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Automatic Service Request (ASR). CVSS 3.0 Base Score 5.1 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3505</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.1</BaseScore>
            <Vector>AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="152" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3506</Title>
      <Notes>
         <Note Audience="All" Ordinal="152" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Web Services).  Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and  12.2.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebLogic Server accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. CVSS 3.0 Base Score 7.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3506</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.0</ProductID>
            <ProductID>P-5242V-12.2.1.1</ProductID>
            <ProductID>P-5242V-12.2.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.4</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.0</ProductID>
            <ProductID>P-5242V-12.2.1.1</ProductID>
            <ProductID>P-5242V-12.2.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="153" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3507</Title>
      <Notes>
         <Note Audience="All" Ordinal="153" Title="Details" Type="Details">Vulnerability in the Oracle Service Bus component of Oracle Fusion Middleware (subcomponent: Web Console Design).  Supported versions that are affected are 12.1.3.0.0, 12.2.1.0.0, 12.2.1.1.0 and 12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Service Bus.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Service Bus accessible data as well as  unauthorized read access to a subset of Oracle Service Bus accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Service Bus. CVSS 3.0 Base Score 7.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3507</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5308V-12.1.3.0.0</ProductID>
            <ProductID>P-5308V-12.2.1.0.0</ProductID>
            <ProductID>P-5308V-12.2.1.1.0</ProductID>
            <ProductID>P-5308V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5308V-12.1.3.0.0</ProductID>
            <ProductID>P-5308V-12.2.1.0.0</ProductID>
            <ProductID>P-5308V-12.2.1.1.0</ProductID>
            <ProductID>P-5308V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="154" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3508</Title>
      <Notes>
         <Note Audience="All" Ordinal="154" Title="Details" Type="Details">Vulnerability in the Primavera Gateway component of Oracle Primavera Products Suite (subcomponent: Primavera Desktop Integration).  Supported versions that are affected are 1.0, 1.1, 14.2, 15.1, 15.2, 16.1 and  16.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Primavera Gateway.  While the vulnerability is in Primavera Gateway, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Primavera Gateway. CVSS 3.0 Base Score 9.1 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3508</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10605V-1.0</ProductID>
            <ProductID>P-10605V-1.1</ProductID>
            <ProductID>P-10605V-14.2</ProductID>
            <ProductID>P-10605V-15.1</ProductID>
            <ProductID>P-10605V-15.2</ProductID>
            <ProductID>P-10605V-16.1</ProductID>
            <ProductID>P-10605V-16.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10605V-1.0</ProductID>
            <ProductID>P-10605V-1.1</ProductID>
            <ProductID>P-10605V-14.2</ProductID>
            <ProductID>P-10605V-15.1</ProductID>
            <ProductID>P-10605V-15.2</ProductID>
            <ProductID>P-10605V-16.1</ProductID>
            <ProductID>P-10605V-16.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="155" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3509</Title>
      <Notes>
         <Note Audience="All" Ordinal="155" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Networking).  Supported versions that are affected are Java SE: 6u141, 7u131 and  8u121; Java SE Embedded: 8u121. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data as well as  unauthorized read access to a subset of Java SE, Java SE Embedded accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 4.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3509</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u141</ProductID>
            <ProductID>P-856V-7u131</ProductID>
            <ProductID>P-856V-8u121; Java SE Embedded: 8u121</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.2</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-856V-Java SE: 6u141</ProductID>
            <ProductID>P-856V-7u131</ProductID>
            <ProductID>P-856V-8u121; Java SE Embedded: 8u121</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="156" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3510</Title>
      <Notes>
         <Note Audience="All" Ordinal="156" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized NIC driver).   The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Solaris.  While the vulnerability is in Solaris, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Solaris accessible data. CVSS 3.0 Base Score 7.7 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3510</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.7</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10006V-11.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="157" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3511</Title>
      <Notes>
         <Note Audience="All" Ordinal="157" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JCE).  Supported versions that are affected are Java SE: 7u131 and  8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE, Java SE Embedded, JRockit executes to compromise Java SE, Java SE Embedded, JRockit.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, Java SE Embedded, JRockit, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE, Java SE Embedded, JRockit.  Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 7.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3511</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 7u131</ProductID>
            <ProductID>P-856V-8u121; Java SE Embedded: 8u121; JRockit: R28.3.13</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.7</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-856V-Java SE: 7u131</ProductID>
            <ProductID>P-856V-8u121; Java SE Embedded: 8u121; JRockit: R28.3.13</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="158" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3512</Title>
      <Notes>
         <Note Audience="All" Ordinal="158" Title="Details" Type="Details">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT).  Supported versions that are affected are Java SE: 7u131 and  8u121. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3512</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 7u131</ProductID>
            <ProductID>P-856V-8u121</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-856V-Java SE: 7u131</ProductID>
            <ProductID>P-856V-8u121</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="159" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3513</Title>
      <Notes>
         <Note Audience="All" Ordinal="159" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).  Supported versions that are affected are Prior to 5.0.38 and  Prior to 5.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 2.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3513</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 5.0.38</ProductID>
            <ProductID>P-8370V-Prior to 5.1.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  2.5</BaseScore>
            <Vector>AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8370V-Prior to 5.0.38</ProductID>
            <ProductID>P-8370V-Prior to 5.1.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="160" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3514</Title>
      <Notes>
         <Note Audience="All" Ordinal="160" Title="Details" Type="Details">Vulnerability in the Java SE component of Oracle Java SE (subcomponent: AWT).  Supported versions that are affected are Java SE: 6u141, 7u131 and  8u121. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3514</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u141</ProductID>
            <ProductID>P-856V-7u131</ProductID>
            <ProductID>P-856V-8u121</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-856V-Java SE: 6u141</ProductID>
            <ProductID>P-856V-7u131</ProductID>
            <ProductID>P-856V-8u121</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="161" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3515</Title>
      <Notes>
         <Note Audience="All" Ordinal="161" Title="Details" Type="Details">Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: User Name/Password Management).  Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and  12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle User Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle User Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle User Management accessible data. CVSS 3.0 Base Score 4.7 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3515</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1475V-12.1.3</ProductID>
            <ProductID>P-1475V-12.2.3</ProductID>
            <ProductID>P-1475V-12.2.4</ProductID>
            <ProductID>P-1475V-12.2.5</ProductID>
            <ProductID>P-1475V-12.2.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1475V-12.1.3</ProductID>
            <ProductID>P-1475V-12.2.3</ProductID>
            <ProductID>P-1475V-12.2.4</ProductID>
            <ProductID>P-1475V-12.2.5</ProductID>
            <ProductID>P-1475V-12.2.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="162" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3516</Title>
      <Notes>
         <Note Audience="All" Ordinal="162" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel Zones virtualized NIC driver).   The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Solaris.  While the vulnerability is in Solaris, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. CVSS 3.0 Base Score 7.7 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3516</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.7</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10006V-11.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="163" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3517</Title>
      <Notes>
         <Note Audience="All" Ordinal="163" Title="Details" Type="Details">Vulnerability in the JD Edwards EnterpriseOne Tools component of Oracle JD Edwards Products (subcomponent: Web Runtime SEC).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise JD Edwards EnterpriseOne Tools.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of JD Edwards EnterpriseOne Tools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of JD Edwards EnterpriseOne Tools. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3517</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4781V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-4781V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="164" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3518</Title>
      <Notes>
         <Note Audience="All" Ordinal="164" Title="Details" Type="Details">Vulnerability in the Enterprise Manager Base Platform component of Oracle Enterprise Manager Grid Control (subcomponent: Discovery Framework).  Supported versions that are affected are 12.1.0, 13.1.0 and  13.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Enterprise Manager Base Platform.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Enterprise Manager Base Platform. CVSS 3.0 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3518</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1370V-12.1.0</ProductID>
            <ProductID>P-1370V-13.1.0</ProductID>
            <ProductID>P-1370V-13.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1370V-12.1.0</ProductID>
            <ProductID>P-1370V-13.1.0</ProductID>
            <ProductID>P-1370V-13.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="165" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3519</Title>
      <Notes>
         <Note Audience="All" Ordinal="165" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Security).  Supported versions that are affected are 8.54 and  8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3519</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="166" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3520</Title>
      <Notes>
         <Note Audience="All" Ordinal="166" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Core).  Supported versions that are affected are 8.54 and  8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.5 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3520</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="167" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3521</Title>
      <Notes>
         <Note Audience="All" Ordinal="167" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise SCM Purchasing component of Oracle PeopleSoft Products (subcomponent: Supplier Registration).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Purchasing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Purchasing accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Purchasing accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3521</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5133V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5133V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="168" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3522</Title>
      <Notes>
         <Note Audience="All" Ordinal="168" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise SCM eSupplier Connection component of Oracle PeopleSoft Products (subcomponent: Vendor).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM eSupplier Connection.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM eSupplier Connection accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM eSupplier Connection accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3522</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5122V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5122V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="169" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3523</Title>
      <Notes>
         <Note Audience="All" Ordinal="169" Title="Details" Type="Details">Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J).  Supported versions that are affected are 5.1.40 and eariler. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors.  While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 8.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3523</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8576V-5.1.40 and eariler</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.5</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8576V-5.1.40 and eariler</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="170" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3524</Title>
      <Notes>
         <Note Audience="All" Ordinal="170" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise SCM Strategic Sourcing component of Oracle PeopleSoft Products (subcomponent: Bidder Registration).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Strategic Sourcing.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Strategic Sourcing accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Strategic Sourcing accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3524</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5136V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5136V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="171" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3525</Title>
      <Notes>
         <Note Audience="All" Ordinal="171" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise SCM Service Procurement component of Oracle PeopleSoft Products (subcomponent: Usability).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM Service Procurement.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM Service Procurement accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM Service Procurement accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3525</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5135V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5135V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="172" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3526</Title>
      <Notes>
         <Note Audience="All" Ordinal="172" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP).  Supported versions that are affected are Java SE: 6u141, 7u131 and  8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded, JRockit.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Java SE, Java SE Embedded, JRockit.  Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3526</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u141</ProductID>
            <ProductID>P-856V-7u131</ProductID>
            <ProductID>P-856V-8u121; Java SE Embedded: 8u121; JRockit: R28.3.13</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-856V-Java SE: 6u141</ProductID>
            <ProductID>P-856V-7u131</ProductID>
            <ProductID>P-856V-8u121; Java SE Embedded: 8u121; JRockit: R28.3.13</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="173" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3527</Title>
      <Notes>
         <Note Audience="All" Ordinal="173" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Core).  Supported versions that are affected are 8.54 and  8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3527</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="174" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3528</Title>
      <Notes>
         <Note Audience="All" Ordinal="174" Title="Details" Type="Details">Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (lists of values, datepicker, etc.)).  Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and  12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Applications Framework accessible data. CVSS 3.0 Base Score 4.7 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3528</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1472V-12.1.3</ProductID>
            <ProductID>P-1472V-12.2.3</ProductID>
            <ProductID>P-1472V-12.2.4</ProductID>
            <ProductID>P-1472V-12.2.5</ProductID>
            <ProductID>P-1472V-12.2.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1472V-12.1.3</ProductID>
            <ProductID>P-1472V-12.2.3</ProductID>
            <ProductID>P-1472V-12.2.4</ProductID>
            <ProductID>P-1472V-12.2.5</ProductID>
            <ProductID>P-1472V-12.2.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="175" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3530</Title>
      <Notes>
         <Note Audience="All" Ordinal="175" Title="Details" Type="Details">Vulnerability in the Oracle Transportation Manager component of Oracle Supply Chain Products Suite (subcomponent: Security).  Supported versions that are affected are 6.2, 6.3.0, 6.3.1, 6.3.2, 6.3.3, 6.3.4, 6.3.5, 6.3.6, 6.3.7, 6.4.0, 6.4.1 and 6.4.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Transportation Manager.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Transportation Manager accessible data as well as  unauthorized access to critical data or complete access to all Oracle Transportation Manager accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3530</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1991V-6.2</ProductID>
            <ProductID>P-1991V-6.3.0</ProductID>
            <ProductID>P-1991V-6.3.1</ProductID>
            <ProductID>P-1991V-6.3.2</ProductID>
            <ProductID>P-1991V-6.3.3</ProductID>
            <ProductID>P-1991V-6.3.4</ProductID>
            <ProductID>P-1991V-6.3.5</ProductID>
            <ProductID>P-1991V-6.3.6</ProductID>
            <ProductID>P-1991V-6.3.7</ProductID>
            <ProductID>P-1991V-6.4.0</ProductID>
            <ProductID>P-1991V-6.4.1</ProductID>
            <ProductID>P-1991V-6.4.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1991V-6.2</ProductID>
            <ProductID>P-1991V-6.3.0</ProductID>
            <ProductID>P-1991V-6.3.1</ProductID>
            <ProductID>P-1991V-6.3.2</ProductID>
            <ProductID>P-1991V-6.3.3</ProductID>
            <ProductID>P-1991V-6.3.4</ProductID>
            <ProductID>P-1991V-6.3.5</ProductID>
            <ProductID>P-1991V-6.3.6</ProductID>
            <ProductID>P-1991V-6.3.7</ProductID>
            <ProductID>P-1991V-6.4.0</ProductID>
            <ProductID>P-1991V-6.4.1</ProductID>
            <ProductID>P-1991V-6.4.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="176" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3531</Title>
      <Notes>
         <Note Audience="All" Ordinal="176" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Servlet Runtime).  Supported versions that are affected are 12.1.3.0, 12.2.1.0, 12.2.1.1 and  12.2.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  While the vulnerability is in Oracle WebLogic Server, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle WebLogic Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebLogic Server. CVSS 3.0 Base Score 7.2 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3531</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-12.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.0</ProductID>
            <ProductID>P-5242V-12.2.1.1</ProductID>
            <ProductID>P-5242V-12.2.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5242V-12.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.0</ProductID>
            <ProductID>P-5242V-12.2.1.1</ProductID>
            <ProductID>P-5242V-12.2.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="177" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3532</Title>
      <Notes>
         <Note Audience="All" Ordinal="177" Title="Details" Type="Details">Vulnerability in the Oracle Retail Warehouse Management System component of Oracle Retail Applications (subcomponent: Security).  Supported versions that are affected are 13.2, 14.0 and  15.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail Warehouse Management System.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Retail Warehouse Management System, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Retail Warehouse Management System accessible data as well as  unauthorized read access to a subset of Oracle Retail Warehouse Management System accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3532</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1847V-13.2</ProductID>
            <ProductID>P-1847V-14.0</ProductID>
            <ProductID>P-1847V-15.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1847V-13.2</ProductID>
            <ProductID>P-1847V-14.0</ProductID>
            <ProductID>P-1847V-15.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="178" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3533</Title>
      <Notes>
         <Note Audience="All" Ordinal="178" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking).  Supported versions that are affected are Java SE: 6u141, 7u131 and  8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via FTP to compromise Java SE, Java SE Embedded, JRockit.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data.  Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3533</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u141</ProductID>
            <ProductID>P-856V-7u131</ProductID>
            <ProductID>P-856V-8u121; Java SE Embedded: 8u121; JRockit: R28.3.13</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-856V-Java SE: 6u141</ProductID>
            <ProductID>P-856V-7u131</ProductID>
            <ProductID>P-856V-8u121; Java SE Embedded: 8u121; JRockit: R28.3.13</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="179" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3534</Title>
      <Notes>
         <Note Audience="All" Ordinal="179" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure).  Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3, 12.1.0, 12.2.0 and 12.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3534</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-12.0.1</ProductID>
            <ProductID>P-9052V-12.0.2</ProductID>
            <ProductID>P-9052V-12.0.3</ProductID>
            <ProductID>P-9052V-12.1.0</ProductID>
            <ProductID>P-9052V-12.2.0</ProductID>
            <ProductID>P-9052V-12.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9052V-12.0.1</ProductID>
            <ProductID>P-9052V-12.0.2</ProductID>
            <ProductID>P-9052V-12.0.3</ProductID>
            <ProductID>P-9052V-12.1.0</ProductID>
            <ProductID>P-9052V-12.2.0</ProductID>
            <ProductID>P-9052V-12.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="180" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3535</Title>
      <Notes>
         <Note Audience="All" Ordinal="180" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure).  Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2 and  12.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Universal Banking.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle FLEXCUBE Universal Banking, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle FLEXCUBE Universal Banking accessible data. CVSS 3.0 Base Score 4.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3535</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9052V-11.3.0</ProductID>
            <ProductID>P-9052V-11.4.0</ProductID>
            <ProductID>P-9052V-12.0.1</ProductID>
            <ProductID>P-9052V-12.0.2</ProductID>
            <ProductID>P-9052V-12.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.7</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9052V-11.3.0</ProductID>
            <ProductID>P-9052V-11.4.0</ProductID>
            <ProductID>P-9052V-12.0.1</ProductID>
            <ProductID>P-9052V-12.0.2</ProductID>
            <ProductID>P-9052V-12.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="181" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3536</Title>
      <Notes>
         <Note Audience="All" Ordinal="181" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Security).  Supported versions that are affected are 8.54 and  8.55. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 4.6 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3536</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.6</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="182" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3537</Title>
      <Notes>
         <Note Audience="All" Ordinal="182" Title="Details" Type="Details">Vulnerability in the Oracle Real-Time Scheduler component of Oracle Utilities Applications (subcomponent: Mobile Communications Platform).  Supported versions that are affected are 2.2.0.3.13, 2.3.0.0 and  2.3.0.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Real-Time Scheduler.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Real-Time Scheduler, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Real-Time Scheduler accessible data as well as  unauthorized read access to a subset of Oracle Real-Time Scheduler accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3537</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2238V-2.2.0.3.13</ProductID>
            <ProductID>P-2238V-2.3.0.0</ProductID>
            <ProductID>P-2238V-2.3.0.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2238V-2.2.0.3.13</ProductID>
            <ProductID>P-2238V-2.3.0.0</ProductID>
            <ProductID>P-2238V-2.3.0.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="183" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3538</Title>
      <Notes>
         <Note Audience="All" Ordinal="183" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Shared Folder).  Supported versions that are affected are Prior to 5.0.34 and  Prior to 5.1.16. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data as well as  unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3538</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 5.0.34</ProductID>
            <ProductID>P-8370V-Prior to 5.1.16</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8370V-Prior to 5.0.34</ProductID>
            <ProductID>P-8370V-Prior to 5.1.16</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="184" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3539</Title>
      <Notes>
         <Note Audience="All" Ordinal="184" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Security).  Supported versions that are affected are Java SE: 6u141, 7u131 and  8u121; Java SE Embedded: 8u121. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Java SE, Java SE Embedded accessible data.  Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability does not apply to Java deployments, typically in servers, that load and run only trusted code (e.g., code installed by an administrator). CVSS 3.0 Base Score 3.1 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3539</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u141</ProductID>
            <ProductID>P-856V-7u131</ProductID>
            <ProductID>P-856V-8u121; Java SE Embedded: 8u121</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-856V-Java SE: 6u141</ProductID>
            <ProductID>P-856V-7u131</ProductID>
            <ProductID>P-856V-8u121; Java SE Embedded: 8u121</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="185" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3540</Title>
      <Notes>
         <Note Audience="All" Ordinal="185" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Server).  Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and  12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle WebCenter Sites as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data and  unauthorized read access to a subset of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3540</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="186" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3541</Title>
      <Notes>
         <Note Audience="All" Ordinal="186" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Server).  Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and  12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3541</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="187" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3542</Title>
      <Notes>
         <Note Audience="All" Ordinal="187" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Server).  Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and  12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3542</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="188" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3543</Title>
      <Notes>
         <Note Audience="All" Ordinal="188" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Server).  Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and  12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3543</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.6</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="189" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3544</Title>
      <Notes>
         <Note Audience="All" Ordinal="189" Title="Details" Type="Details">Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking).  Supported versions that are affected are Java SE: 6u141, 7u131 and  8u121; Java SE Embedded: 8u121; JRockit: R28.3.13. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SMTP to compromise Java SE, Java SE Embedded, JRockit.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Java SE, Java SE Embedded, JRockit accessible data.  Note: Applies to client and server deployment of Java. This vulnerability can be exploited through sandboxed Java Web Start applications and sandboxed Java applets. It can also be exploited by supplying data to APIs in the specified Component without using sandboxed Java Web Start applications or sandboxed Java applets, such as through a web service. CVSS 3.0 Base Score 3.7 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3544</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-856V-Java SE: 6u141</ProductID>
            <ProductID>P-856V-7u131</ProductID>
            <ProductID>P-856V-8u121; Java SE Embedded: 8u121; JRockit: R28.3.13</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-856V-Java SE: 6u141</ProductID>
            <ProductID>P-856V-7u131</ProductID>
            <ProductID>P-856V-8u121; Java SE Embedded: 8u121; JRockit: R28.3.13</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="190" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3545</Title>
      <Notes>
         <Note Audience="All" Ordinal="190" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Blob Server).  Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and  12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Sites accessible data as well as  unauthorized read access to a subset of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3545</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="191" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3546</Title>
      <Notes>
         <Note Audience="All" Ordinal="191" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework).  Supported versions that are affected are 8.54 and  8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of PeopleSoft Enterprise PeopleTools accessible data as well as  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3546</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="192" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3547</Title>
      <Notes>
         <Note Audience="All" Ordinal="192" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: MultiChannel Framework).  Supported versions that are affected are 8.54 and  8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PeopleTools, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 7.4 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3547</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.4</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="193" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3548</Title>
      <Notes>
         <Note Audience="All" Ordinal="193" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker).  Supported versions that are affected are 8.54 and  8.55. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PeopleSoft Enterprise PeopleTools. CVSS 3.0 Base Score 6.5 (Confidentiality and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3548</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5085V-8.54</ProductID>
            <ProductID>P-5085V-8.55</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="194" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3549</Title>
      <Notes>
         <Note Audience="All" Ordinal="194" Title="Details" Type="Details">Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and  12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Scripting accessible data as well as  unauthorized access to critical data or complete access to all Oracle Scripting accessible data. CVSS 3.0 Base Score 9.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3549</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-433V-12.1.1</ProductID>
            <ProductID>P-433V-12.1.2</ProductID>
            <ProductID>P-433V-12.1.3</ProductID>
            <ProductID>P-433V-12.2.3</ProductID>
            <ProductID>P-433V-12.2.4</ProductID>
            <ProductID>P-433V-12.2.5</ProductID>
            <ProductID>P-433V-12.2.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-433V-12.1.1</ProductID>
            <ProductID>P-433V-12.1.2</ProductID>
            <ProductID>P-433V-12.1.3</ProductID>
            <ProductID>P-433V-12.2.3</ProductID>
            <ProductID>P-433V-12.2.4</ProductID>
            <ProductID>P-433V-12.2.5</ProductID>
            <ProductID>P-433V-12.2.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="195" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3550</Title>
      <Notes>
         <Note Audience="All" Ordinal="195" Title="Details" Type="Details">Vulnerability in the Oracle Customer Interaction History component of Oracle E-Business Suite (subcomponent: Admin Console).  Supported versions that are affected are 12.1.1, 12.1.2 and  12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Customer Interaction History.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Customer Interaction History, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Customer Interaction History accessible data as well as  unauthorized update, insert or delete access to some of Oracle Customer Interaction History accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3550</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1374V-12.1.1</ProductID>
            <ProductID>P-1374V-12.1.2</ProductID>
            <ProductID>P-1374V-12.1.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1374V-12.1.1</ProductID>
            <ProductID>P-1374V-12.1.2</ProductID>
            <ProductID>P-1374V-12.1.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="196" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3551</Title>
      <Notes>
         <Note Audience="All" Ordinal="196" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Smartcard Libraries).   The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris as well as  unauthorized update, insert or delete access to some of Solaris accessible data and  unauthorized read access to a subset of Solaris accessible data. CVSS 3.0 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3551</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.6</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10006V-11.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="197" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3552</Title>
      <Notes>
         <Note Audience="All" Ordinal="197" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OPERA Room Image/Picture Setup).  Supported versions that are affected are 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x and 5.5.1.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hospitality OPERA 5 Property Services accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3552</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11580V-5.4.0.x</ProductID>
            <ProductID>P-11580V-5.4.1.x</ProductID>
            <ProductID>P-11580V-5.4.2.x</ProductID>
            <ProductID>P-11580V-5.4.3.x</ProductID>
            <ProductID>P-11580V-5.5.0.x</ProductID>
            <ProductID>P-11580V-5.5.1.x</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-11580V-5.4.0.x</ProductID>
            <ProductID>P-11580V-5.4.1.x</ProductID>
            <ProductID>P-11580V-5.4.2.x</ProductID>
            <ProductID>P-11580V-5.4.3.x</ProductID>
            <ProductID>P-11580V-5.5.0.x</ProductID>
            <ProductID>P-11580V-5.5.1.x</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="198" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3553</Title>
      <Notes>
         <Note Audience="All" Ordinal="198" Title="Details" Type="Details">Vulnerability in the Oracle Identity Manager component of Oracle Fusion Middleware (subcomponent: Rules Engine).   The supported version that is affected is 11.1.2.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Identity Manager.  While the vulnerability is in Oracle Identity Manager, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3553</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1980V-11.1.2.3.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.9</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1980V-11.1.2.3.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="199" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3554</Title>
      <Notes>
         <Note Audience="All" Ordinal="199" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Catalog Mover).  Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and  12.2.1.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Sites accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3554</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="200" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3555</Title>
      <Notes>
         <Note Audience="All" Ordinal="200" Title="Details" Type="Details">Vulnerability in the Oracle iReceivables component of Oracle E-Business Suite (subcomponent: Self Registration).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and  12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iReceivables.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle iReceivables. CVSS 3.0 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3555</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1106V-12.1.1</ProductID>
            <ProductID>P-1106V-12.1.2</ProductID>
            <ProductID>P-1106V-12.1.3</ProductID>
            <ProductID>P-1106V-12.2.3</ProductID>
            <ProductID>P-1106V-12.2.4</ProductID>
            <ProductID>P-1106V-12.2.5</ProductID>
            <ProductID>P-1106V-12.2.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1106V-12.1.1</ProductID>
            <ProductID>P-1106V-12.1.2</ProductID>
            <ProductID>P-1106V-12.1.3</ProductID>
            <ProductID>P-1106V-12.2.3</ProductID>
            <ProductID>P-1106V-12.2.4</ProductID>
            <ProductID>P-1106V-12.2.5</ProductID>
            <ProductID>P-1106V-12.2.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="201" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3556</Title>
      <Notes>
         <Note Audience="All" Ordinal="201" Title="Details" Type="Details">Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: File Management).  Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and  12.2.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Application Object Library accessible data. CVSS 3.0 Base Score 3.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3556</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-510V-12.1.3</ProductID>
            <ProductID>P-510V-12.2.3</ProductID>
            <ProductID>P-510V-12.2.4</ProductID>
            <ProductID>P-510V-12.2.5</ProductID>
            <ProductID>P-510V-12.2.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.7</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-510V-12.1.3</ProductID>
            <ProductID>P-510V-12.2.3</ProductID>
            <ProductID>P-510V-12.2.4</ProductID>
            <ProductID>P-510V-12.2.5</ProductID>
            <ProductID>P-510V-12.2.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="202" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3557</Title>
      <Notes>
         <Note Audience="All" Ordinal="202" Title="Details" Type="Details">Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Print Server).  Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and  12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data as well as  unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3557</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1379V-12.1.3</ProductID>
            <ProductID>P-1379V-12.2.3</ProductID>
            <ProductID>P-1379V-12.2.4</ProductID>
            <ProductID>P-1379V-12.2.5</ProductID>
            <ProductID>P-1379V-12.2.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-1379V-12.1.3</ProductID>
            <ProductID>P-1379V-12.2.3</ProductID>
            <ProductID>P-1379V-12.2.4</ProductID>
            <ProductID>P-1379V-12.2.5</ProductID>
            <ProductID>P-1379V-12.2.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="203" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3558</Title>
      <Notes>
         <Note Audience="All" Ordinal="203" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).  Supported versions that are affected are Prior to 5.0.38 and  Prior to 5.1.20. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as  unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and  unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 8.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3558</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 5.0.38</ProductID>
            <ProductID>P-8370V-Prior to 5.1.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.5</BaseScore>
            <Vector>AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8370V-Prior to 5.0.38</ProductID>
            <ProductID>P-8370V-Prior to 5.1.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="204" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3559</Title>
      <Notes>
         <Note Audience="All" Ordinal="204" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).  Supported versions that are affected are Prior to 5.0.38 and  Prior to 5.1.20. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as  unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and  unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 7.9 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3559</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 5.0.38</ProductID>
            <ProductID>P-8370V-Prior to 5.1.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.9</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8370V-Prior to 5.0.38</ProductID>
            <ProductID>P-8370V-Prior to 5.1.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="205" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3560</Title>
      <Notes>
         <Note Audience="All" Ordinal="205" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OXI Interface).  Supported versions that are affected are 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x and 5.5.1.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle Hospitality OPERA 5 Property Services accessible data. CVSS 3.0 Base Score 4.3 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3560</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11580V-5.4.0.x</ProductID>
            <ProductID>P-11580V-5.4.1.x</ProductID>
            <ProductID>P-11580V-5.4.2.x</ProductID>
            <ProductID>P-11580V-5.4.3.x</ProductID>
            <ProductID>P-11580V-5.5.0.x</ProductID>
            <ProductID>P-11580V-5.5.1.x</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  4.3</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-11580V-5.4.0.x</ProductID>
            <ProductID>P-11580V-5.4.1.x</ProductID>
            <ProductID>P-11580V-5.4.2.x</ProductID>
            <ProductID>P-11580V-5.4.3.x</ProductID>
            <ProductID>P-11580V-5.5.0.x</ProductID>
            <ProductID>P-11580V-5.5.1.x</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="206" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3561</Title>
      <Notes>
         <Note Audience="All" Ordinal="206" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).  Supported versions that are affected are Prior to 5.0.38 and  Prior to 5.1.20. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3561</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 5.0.38</ProductID>
            <ProductID>P-8370V-Prior to 5.1.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8370V-Prior to 5.0.38</ProductID>
            <ProductID>P-8370V-Prior to 5.1.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="207" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3563</Title>
      <Notes>
         <Note Audience="All" Ordinal="207" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).  Supported versions that are affected are Prior to 5.0.38 and  Prior to 5.1.20. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3563</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 5.0.38</ProductID>
            <ProductID>P-8370V-Prior to 5.1.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8370V-Prior to 5.0.38</ProductID>
            <ProductID>P-8370V-Prior to 5.1.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="208" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3564</Title>
      <Notes>
         <Note Audience="All" Ordinal="208" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RBAC).   The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Solaris. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3564</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10006V-11.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="209" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3565</Title>
      <Notes>
         <Note Audience="All" Ordinal="209" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: RBAC).   The supported version that is affected is 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Solaris accessible data as well as  unauthorized access to critical data or complete access to all Solaris accessible data. CVSS 3.0 Base Score 7.9 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3565</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-11.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.9</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10006V-11.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="210" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3567</Title>
      <Notes>
         <Note Audience="All" Ordinal="210" Title="Details" Type="Details">Vulnerability in the OJVM component of Oracle Database Server.  Supported versions that are affected are 11.2.0.4 and  12.1.0.2. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise OJVM.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of OJVM. CVSS 3.0 Base Score 5.3 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3567</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5V-11.2.0.4</ProductID>
            <ProductID>P-5V-12.1.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="211" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3568</Title>
      <Notes>
         <Note Audience="All" Ordinal="211" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OPERA Printing and Login).  Supported versions that are affected are 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x and 5.5.1.x. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle Hospitality OPERA 5 Property Services executes to compromise Oracle Hospitality OPERA 5 Property Services.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Hospitality OPERA 5 Property Services accessible data as well as  unauthorized access to critical data or complete access to all Oracle Hospitality OPERA 5 Property Services accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Hospitality OPERA 5 Property Services. CVSS 3.0 Base Score 6.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3568</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11580V-5.4.0.x</ProductID>
            <ProductID>P-11580V-5.4.1.x</ProductID>
            <ProductID>P-11580V-5.4.2.x</ProductID>
            <ProductID>P-11580V-5.4.3.x</ProductID>
            <ProductID>P-11580V-5.5.0.x</ProductID>
            <ProductID>P-11580V-5.5.1.x</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-11580V-5.4.0.x</ProductID>
            <ProductID>P-11580V-5.4.1.x</ProductID>
            <ProductID>P-11580V-5.4.2.x</ProductID>
            <ProductID>P-11580V-5.4.3.x</ProductID>
            <ProductID>P-11580V-5.5.0.x</ProductID>
            <ProductID>P-11580V-5.5.1.x</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="212" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3569</Title>
      <Notes>
         <Note Audience="All" Ordinal="212" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OPERA Business Events).  Supported versions that are affected are 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x and 5.5.1.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hospitality OPERA 5 Property Services accessible data as well as  unauthorized read access to a subset of Oracle Hospitality OPERA 5 Property Services accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3569</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11580V-5.4.0.x</ProductID>
            <ProductID>P-11580V-5.4.1.x</ProductID>
            <ProductID>P-11580V-5.4.2.x</ProductID>
            <ProductID>P-11580V-5.4.3.x</ProductID>
            <ProductID>P-11580V-5.5.0.x</ProductID>
            <ProductID>P-11580V-5.5.1.x</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-11580V-5.4.0.x</ProductID>
            <ProductID>P-11580V-5.4.1.x</ProductID>
            <ProductID>P-11580V-5.4.2.x</ProductID>
            <ProductID>P-11580V-5.4.3.x</ProductID>
            <ProductID>P-11580V-5.5.0.x</ProductID>
            <ProductID>P-11580V-5.5.1.x</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="213" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3570</Title>
      <Notes>
         <Note Audience="All" Ordinal="213" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: eSettlements).   The supported version that is affected is 9.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise FSCM.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise FSCM accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise FSCM accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3570</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4987V-9.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-4987V-9.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="214" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3571</Title>
      <Notes>
         <Note Audience="All" Ordinal="214" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise SCM eBill Payment component of Oracle PeopleSoft Products (subcomponent: Security).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise SCM eBill Payment.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise SCM eBill Payment accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise SCM eBill Payment accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3571</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5115V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5115V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="215" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3572</Title>
      <Notes>
         <Note Audience="All" Ordinal="215" Title="Details" Type="Details">Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component of Oracle Commerce (subcomponent: MDEX).  Supported versions that are affected are 6.2.2, 6.3.0, 6.4.1.2, 6.5.0, 6.5.1 and  6.5.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Guided Search / Oracle Commerce Experience Manager.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Commerce Guided Search / Oracle Commerce Experience Manager. CVSS 3.0 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3572</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9633V-6.2.2</ProductID>
            <ProductID>P-9633V-6.3.0</ProductID>
            <ProductID>P-9633V-6.4.1.2</ProductID>
            <ProductID>P-9633V-6.5.0</ProductID>
            <ProductID>P-9633V-6.5.1</ProductID>
            <ProductID>P-9633V-6.5.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9633V-6.2.2</ProductID>
            <ProductID>P-9633V-6.3.0</ProductID>
            <ProductID>P-9633V-6.4.1.2</ProductID>
            <ProductID>P-9633V-6.5.0</ProductID>
            <ProductID>P-9633V-6.5.1</ProductID>
            <ProductID>P-9633V-6.5.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="216" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3573</Title>
      <Notes>
         <Note Audience="All" Ordinal="216" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OPERA Printing).  Supported versions that are affected are 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x and 5.5.1.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Hospitality OPERA 5 Property Services, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Oracle Hospitality OPERA 5 Property Services accessible data as well as  unauthorized read access to a subset of Oracle Hospitality OPERA 5 Property Services accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3573</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11580V-5.4.0.x</ProductID>
            <ProductID>P-11580V-5.4.1.x</ProductID>
            <ProductID>P-11580V-5.4.2.x</ProductID>
            <ProductID>P-11580V-5.4.3.x</ProductID>
            <ProductID>P-11580V-5.5.0.x</ProductID>
            <ProductID>P-11580V-5.5.1.x</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-11580V-5.4.0.x</ProductID>
            <ProductID>P-11580V-5.4.1.x</ProductID>
            <ProductID>P-11580V-5.4.2.x</ProductID>
            <ProductID>P-11580V-5.4.3.x</ProductID>
            <ProductID>P-11580V-5.5.0.x</ProductID>
            <ProductID>P-11580V-5.5.1.x</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="217" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3574</Title>
      <Notes>
         <Note Audience="All" Ordinal="217" Title="Details" Type="Details">Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OPERA License code configuration).  Supported versions that are affected are 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x and 5.5.1.x. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Hospitality OPERA 5 Property Services.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Hospitality OPERA 5 Property Services accessible data as well as  unauthorized update, insert or delete access to some of Oracle Hospitality OPERA 5 Property Services accessible data. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3574</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11580V-5.4.0.x</ProductID>
            <ProductID>P-11580V-5.4.1.x</ProductID>
            <ProductID>P-11580V-5.4.2.x</ProductID>
            <ProductID>P-11580V-5.4.3.x</ProductID>
            <ProductID>P-11580V-5.5.0.x</ProductID>
            <ProductID>P-11580V-5.5.1.x</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-11580V-5.4.0.x</ProductID>
            <ProductID>P-11580V-5.4.1.x</ProductID>
            <ProductID>P-11580V-5.4.2.x</ProductID>
            <ProductID>P-11580V-5.4.3.x</ProductID>
            <ProductID>P-11580V-5.5.0.x</ProductID>
            <ProductID>P-11580V-5.5.1.x</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="218" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3575</Title>
      <Notes>
         <Note Audience="All" Ordinal="218" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).  Supported versions that are affected are Prior to 5.0.38 and  Prior to 5.1.20. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 7.9 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3575</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 5.0.38</ProductID>
            <ProductID>P-8370V-Prior to 5.1.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.9</BaseScore>
            <Vector>AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8370V-Prior to 5.0.38</ProductID>
            <ProductID>P-8370V-Prior to 5.1.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="219" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3576</Title>
      <Notes>
         <Note Audience="All" Ordinal="219" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).  Supported versions that are affected are Prior to 5.0.38 and  Prior to 5.1.20. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3576</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 5.0.38</ProductID>
            <ProductID>P-8370V-Prior to 5.1.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8370V-Prior to 5.0.38</ProductID>
            <ProductID>P-8370V-Prior to 5.1.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="220" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3577</Title>
      <Notes>
         <Note Audience="All" Ordinal="220" Title="Details" Type="Details">Vulnerability in the PeopleSoft Enterprise CS Campus Community component of Oracle PeopleSoft Products (subcomponent: Frameworks).   The supported version that is affected is 9.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all PeopleSoft Enterprise CS Campus Community accessible data as well as  unauthorized access to critical data or complete access to all PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3577</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5183V-9.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5183V-9.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="221" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3578</Title>
      <Notes>
         <Note Audience="All" Ordinal="221" Title="Details" Type="Details">Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: RAS subsystems).   The supported version that is affected is AK 2013. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Sun ZFS Storage Appliance Kit (AK) executes to compromise Sun ZFS Storage Appliance Kit (AK).  While the vulnerability is in Sun ZFS Storage Appliance Kit (AK), attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Sun ZFS Storage Appliance Kit (AK). CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3578</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10026V-AK 2013</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10026V-AK 2013</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="222" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3579</Title>
      <Notes>
         <Note Audience="All" Ordinal="222" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access).  Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and  16.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Primavera P6 Enterprise Project Portfolio Management, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized read access to a subset of Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3579</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
            <ProductID>P-5579V-16.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
            <ProductID>P-5579V-16.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="223" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3580</Title>
      <Notes>
         <Note Audience="All" Ordinal="223" Title="Details" Type="Details">Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: RAS subsystems).   The supported version that is affected is AK 2013. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Sun ZFS Storage Appliance Kit (AK).  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Sun ZFS Storage Appliance Kit (AK), attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Sun ZFS Storage Appliance Kit (AK). CVSS 3.0 Base Score 8.3 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3580</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10026V-AK 2013</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.3</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10026V-AK 2013</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="224" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3581</Title>
      <Notes>
         <Note Audience="All" Ordinal="224" Title="Details" Type="Details">Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager).   The supported version that is affected is Prior to 5.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Automatic Service Request (ASR) executes to compromise Automatic Service Request (ASR).  Successful attacks of this vulnerability can result in takeover of Automatic Service Request (ASR). CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3581</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="225" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3582</Title>
      <Notes>
         <Note Audience="All" Ordinal="225" Title="Details" Type="Details">Vulnerability in the Oracle SuperCluster Specific Software component of Oracle Sun Systems Products Suite (subcomponent: Backup/Restore Utility).  Supported versions that are affected are 2.3.8 and  2.3.13. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle SuperCluster Specific Software executes to compromise Oracle SuperCluster Specific Software.  Successful attacks of this vulnerability can result in takeover of Oracle SuperCluster Specific Software. CVSS 3.0 Base Score 8.4 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3582</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10011V-2.3.8</ProductID>
            <ProductID>P-10011V-2.3.13</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.4</BaseScore>
            <Vector>AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10011V-2.3.8</ProductID>
            <ProductID>P-10011V-2.3.13</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="226" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3583</Title>
      <Notes>
         <Note Audience="All" Ordinal="226" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Web Access).  Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and  16.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Primavera P6 Enterprise Project Portfolio Management accessible data as well as  unauthorized access to critical data or complete access to all Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3583</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
            <ProductID>P-5579V-16.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5579V-8.3</ProductID>
            <ProductID>P-5579V-8.4</ProductID>
            <ProductID>P-5579V-15.1</ProductID>
            <ProductID>P-5579V-15.2</ProductID>
            <ProductID>P-5579V-16.1</ProductID>
            <ProductID>P-5579V-16.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="227" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3584</Title>
      <Notes>
         <Note Audience="All" Ordinal="227" Title="Details" Type="Details">Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: RAS subsystems).   The supported version that is affected is AK 2013. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Sun ZFS Storage Appliance Kit (AK) executes to compromise Sun ZFS Storage Appliance Kit (AK).  While the vulnerability is in Sun ZFS Storage Appliance Kit (AK), attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Sun ZFS Storage Appliance Kit (AK). CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3584</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10026V-AK 2013</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10026V-AK 2013</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="228" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3585</Title>
      <Notes>
         <Note Audience="All" Ordinal="228" Title="Details" Type="Details">Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: User Interface subsystem).   The supported version that is affected is AK 2013. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Sun ZFS Storage Appliance Kit (AK).  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of Sun ZFS Storage Appliance Kit (AK) accessible data. CVSS 3.0 Base Score 5.3 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3585</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10026V-AK 2013</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.3</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10026V-AK 2013</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="229" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3586</Title>
      <Notes>
         <Note Audience="All" Ordinal="229" Title="Details" Type="Details">Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J).  Supported versions that are affected are 5.1.41 and earlier. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors.  While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Connectors accessible data as well as  unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.0 Base Score 6.4 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3586</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8576V-5.1.41 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.4</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8576V-5.1.41 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="230" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3587</Title>
      <Notes>
         <Note Audience="All" Ordinal="230" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Shared Folder).  Supported versions that are affected are Prior to 5.0.38 and  Prior to 5.1.20. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.  While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.4 (Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3587</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-Prior to 5.0.38</ProductID>
            <ProductID>P-8370V-Prior to 5.1.20</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.4</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8370V-Prior to 5.0.38</ProductID>
            <ProductID>P-8370V-Prior to 5.1.20</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="231" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3589</Title>
      <Notes>
         <Note Audience="All" Ordinal="231" Title="Details" Type="Details">Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J).  Supported versions that are affected are 5.1.41 and earlier. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Connectors accessible data. CVSS 3.0 Base Score 3.3 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3589</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8576V-5.1.41 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.3</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8576V-5.1.41 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="232" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3590</Title>
      <Notes>
         <Note Audience="All" Ordinal="232" Title="Details" Type="Details">Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Python).  Supported versions that are affected are 2.1.5 and earlier. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in  unauthorized update, insert or delete access to some of MySQL Connectors accessible data. CVSS 3.0 Base Score 3.3 (Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3590</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8576V-2.1.5 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.3</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8576V-2.1.5 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="233" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3591</Title>
      <Notes>
         <Note Audience="All" Ordinal="233" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Catalog Mover).  Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and  12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Sites accessible data as well as  unauthorized read access to a subset of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3591</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="234" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3592</Title>
      <Notes>
         <Note Audience="All" Ordinal="234" Title="Details" Type="Details">Vulnerability in the Oracle Payables component of Oracle E-Business Suite (subcomponent: Self Service Manager).  Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and  12.2.6. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Payables.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle Payables accessible data as well as  unauthorized access to critical data or complete access to all Oracle Payables accessible data. CVSS 3.0 Base Score 6.5 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3592</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-506V-12.1.1</ProductID>
            <ProductID>P-506V-12.1.2</ProductID>
            <ProductID>P-506V-12.1.3</ProductID>
            <ProductID>P-506V-12.2.3</ProductID>
            <ProductID>P-506V-12.2.4</ProductID>
            <ProductID>P-506V-12.2.5</ProductID>
            <ProductID>P-506V-12.2.6</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.5</BaseScore>
            <Vector>AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-506V-12.1.1</ProductID>
            <ProductID>P-506V-12.1.2</ProductID>
            <ProductID>P-506V-12.1.3</ProductID>
            <ProductID>P-506V-12.2.3</ProductID>
            <ProductID>P-506V-12.2.4</ProductID>
            <ProductID>P-506V-12.2.5</ProductID>
            <ProductID>P-506V-12.2.6</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="235" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3593</Title>
      <Notes>
         <Note Audience="All" Ordinal="235" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI).  Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and  12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3593</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="236" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3594</Title>
      <Notes>
         <Note Audience="All" Ordinal="236" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI).  Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and  12.2.1.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3594</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="237" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3595</Title>
      <Notes>
         <Note Audience="All" Ordinal="237" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI).  Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and  12.2.1.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3595</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="238" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3596</Title>
      <Notes>
         <Note Audience="All" Ordinal="238" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI).  Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and  12.2.1.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Sites accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Sites. CVSS 3.0 Base Score 7.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3596</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.6</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="239" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3597</Title>
      <Notes>
         <Note Audience="All" Ordinal="239" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI).  Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and  12.2.1.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 5.7 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3597</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.7</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="240" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3598</Title>
      <Notes>
         <Note Audience="All" Ordinal="240" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI).  Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and  12.2.1.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3598</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="241" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3599</Title>
      <Notes>
         <Note Audience="All" Ordinal="241" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth).  Supported versions that are affected are 5.6.35 and earlier and  5.7.17 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3599</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="242" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3600</Title>
      <Notes>
         <Note Audience="All" Ordinal="242" Title="Details" Type="Details">Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Client mysqldump).  Supported versions that are affected are 5.5.54 and earlier, 5.6.35 and earlier and  5.7.17 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.  Successful attacks of this vulnerability can result in takeover of MySQL Server.  Note: CVE-2017-3600 is equivalent to CVE-2016-5483. CVSS 3.0 Base Score 6.6 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3600</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  6.6</BaseScore>
            <Vector>AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8478V-5.5.54 and earlier</ProductID>
            <ProductID>P-8478V-5.6.35 and earlier</ProductID>
            <ProductID>P-8478V-5.7.17 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="243" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3601</Title>
      <Notes>
         <Note Audience="All" Ordinal="243" Title="Details" Type="Details">Vulnerability in the Oracle API Gateway component of Oracle Fusion Middleware (subcomponent: Oracle API Gateway).   The supported version that is affected is 11.1.2.4.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle API Gateway.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle API Gateway accessible data as well as  unauthorized access to critical data or complete access to all Oracle API Gateway accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3601</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9195V-11.1.2.4.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9195V-11.1.2.4.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="244" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3602</Title>
      <Notes>
         <Note Audience="All" Ordinal="244" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI).  Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and  12.2.1.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Sites accessible data as well as  unauthorized access to critical data or complete access to all Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3602</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.1</BaseScore>
            <Vector>AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="245" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3603</Title>
      <Notes>
         <Note Audience="All" Ordinal="245" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Advanced UI).  Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and  12.2.1.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Sites.  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle WebCenter Sites accessible data. CVSS 3.0 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3603</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="246" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3604</Title>
      <Notes>
         <Note Audience="All" Ordinal="246" Title="Details" Type="Details">Vulnerability in the Data Store component of Oracle Berkeley DB.   The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Data Store. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3604</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="247" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3605</Title>
      <Notes>
         <Note Audience="All" Ordinal="247" Title="Details" Type="Details">Vulnerability in the Data Store component of Oracle Berkeley DB.   The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Data Store. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3605</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="248" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3606</Title>
      <Notes>
         <Note Audience="All" Ordinal="248" Title="Details" Type="Details">Vulnerability in the Data Store component of Oracle Berkeley DB.   The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Data Store. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3606</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="249" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3607</Title>
      <Notes>
         <Note Audience="All" Ordinal="249" Title="Details" Type="Details">Vulnerability in the Data Store component of Oracle Berkeley DB.   The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Data Store. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3607</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="250" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3608</Title>
      <Notes>
         <Note Audience="All" Ordinal="250" Title="Details" Type="Details">Vulnerability in the Data Store component of Oracle Berkeley DB.   The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Data Store. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3608</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="251" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3609</Title>
      <Notes>
         <Note Audience="All" Ordinal="251" Title="Details" Type="Details">Vulnerability in the Data Store component of Oracle Berkeley DB.   The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Data Store. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3609</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="252" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3610</Title>
      <Notes>
         <Note Audience="All" Ordinal="252" Title="Details" Type="Details">Vulnerability in the Data Store component of Oracle Berkeley DB.   The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Data Store. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3610</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="253" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3611</Title>
      <Notes>
         <Note Audience="All" Ordinal="253" Title="Details" Type="Details">Vulnerability in the Data Store component of Oracle Berkeley DB.   The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Data Store. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3611</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="254" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3612</Title>
      <Notes>
         <Note Audience="All" Ordinal="254" Title="Details" Type="Details">Vulnerability in the Data Store component of Oracle Berkeley DB.   The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Data Store. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3612</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="255" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3613</Title>
      <Notes>
         <Note Audience="All" Ordinal="255" Title="Details" Type="Details">Vulnerability in the Data Store component of Oracle Berkeley DB.   The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Data Store. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3613</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="256" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3614</Title>
      <Notes>
         <Note Audience="All" Ordinal="256" Title="Details" Type="Details">Vulnerability in the Data Store component of Oracle Berkeley DB.   The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Data Store. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3614</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="257" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3615</Title>
      <Notes>
         <Note Audience="All" Ordinal="257" Title="Details" Type="Details">Vulnerability in the Data Store component of Oracle Berkeley DB.   The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Data Store. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3615</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="258" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3616</Title>
      <Notes>
         <Note Audience="All" Ordinal="258" Title="Details" Type="Details">Vulnerability in the Data Store component of Oracle Berkeley DB.   The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Data Store. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3616</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="259" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3617</Title>
      <Notes>
         <Note Audience="All" Ordinal="259" Title="Details" Type="Details">Vulnerability in the Data Store component of Oracle Berkeley DB.   The supported version that is affected is Prior to 6.2.32. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Data Store executes to compromise Data Store.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Data Store. CVSS 3.0 Base Score 7.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3617</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.0</BaseScore>
            <Vector>AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2051V-Prior to 6.2.32</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="260" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3618</Title>
      <Notes>
         <Note Audience="All" Ordinal="260" Title="Details" Type="Details">Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager).   The supported version that is affected is Prior to 5.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Automatic Service Request (ASR) executes to compromise Automatic Service Request (ASR).  Successful attacks of this vulnerability can result in  unauthorized creation, deletion or modification access to critical data or all Automatic Service Request (ASR) accessible data as well as  unauthorized access to critical data or complete access to all Automatic Service Request (ASR) accessible data. CVSS 3.0 Base Score 7.1 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3618</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.1</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="261" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3619</Title>
      <Notes>
         <Note Audience="All" Ordinal="261" Title="Details" Type="Details">Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager).   The supported version that is affected is Prior to 5.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Automatic Service Request (ASR) executes to compromise Automatic Service Request (ASR).  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Automatic Service Request (ASR) accessible data. CVSS 3.0 Base Score 5.5 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3619</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.5</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="262" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3620</Title>
      <Notes>
         <Note Audience="All" Ordinal="262" Title="Details" Type="Details">Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager).   The supported version that is affected is Prior to 5.7. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Automatic Service Request (ASR) executes to compromise Automatic Service Request (ASR).  Successful attacks of this vulnerability can result in takeover of Automatic Service Request (ASR). CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3620</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9042V-Prior to 5.7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="263" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3621</Title>
      <Notes>
         <Note Audience="All" Ordinal="263" Title="Details" Type="Details">Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: IPC Frameworks).   The supported version that is affected is AK 2013. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Sun ZFS Storage Appliance Kit (AK).  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Sun ZFS Storage Appliance Kit (AK). CVSS 3.0 Base Score 7.5 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3621</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10026V-AK 2013</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.5</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10026V-AK 2013</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="264" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3622</Title>
      <Notes>
         <Note Audience="All" Ordinal="264" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (CDE)).   The supported version that is affected is 10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris.  Successful attacks of this vulnerability can result in takeover of Solaris.  Note: CVE-2017-3622 is assigned for the "Extremeparr". CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3622</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-10</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  7.8</BaseScore>
            <Vector>AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10006V-10</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="265" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3623</Title>
      <Notes>
         <Note Audience="All" Ordinal="265" Title="Details" Type="Details">Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported versions that are affected see note. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Solaris.  While the vulnerability is in Solaris, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Solaris.  Note: CVE-2017-3623 is assigned for "Ebbisland". Solaris 10 systems which have had any Kernel patch installed after, or updated via patching tools since 2012-01-26 are not impacted. Also, any Solaris 10 system installed with Solaris 10 1/13 (Solaris 10 Update 11) are not vulnerable. Solaris 11 is not impacted by this issue. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3623</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10006V-None</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10006V-None</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="266" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3625</Title>
      <Notes>
         <Note Audience="All" Ordinal="266" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Content component of Oracle Fusion Middleware (subcomponent: Content Server).  Supported versions that are affected are 11.1.1.7, 11.1.1.9, 12.2.1.0, 12.2.1.1 and 12.2.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Content.  Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle WebCenter Content, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle WebCenter Content accessible data as well as  unauthorized update, insert or delete access to some of Oracle WebCenter Content accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3625</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-2271V-11.1.1.7</ProductID>
            <ProductID>P-2271V-11.1.1.9</ProductID>
            <ProductID>P-2271V-12.2.1.0</ProductID>
            <ProductID>P-2271V-12.2.1.1</ProductID>
            <ProductID>P-2271V-12.2.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  8.2</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-2271V-11.1.1.7</ProductID>
            <ProductID>P-2271V-11.1.1.9</ProductID>
            <ProductID>P-2271V-12.2.1.0</ProductID>
            <ProductID>P-2271V-12.2.1.1</ProductID>
            <ProductID>P-2271V-12.2.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="267" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3626</Title>
      <Notes>
         <Note Audience="All" Ordinal="267" Title="Details" Type="Details">Vulnerability in the Oracle GlassFish Server component of Oracle Fusion Middleware (subcomponent: Java Server Faces).   The supported version that is affected is 3.1.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle GlassFish Server.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Oracle GlassFish Server accessible data. CVSS 3.0 Base Score 3.1 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3626</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8493V-3.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  3.1</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8493V-3.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="268" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3731</Title>
      <Notes>
         <Note Audience="All" Ordinal="268" Title="Details" Type="Details">Vulnerability in the MySQL Enterprise Monitor component of Oracle MySQL (subcomponent: Monitoring: General (OpenSSL)).  Supported versions that are affected are 3.1.6.8003 and earlier, 
3.2.1182 and earlier and  
3.3.2.1162 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Enterprise Monitor accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3731</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8480V-3.1.6.8003 and earlier</ProductID>
            <ProductID>P-8480V-3.2.1182 and earlier</ProductID>
            <ProductID>P-8480V-3.3.2.1162 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8480V-3.1.6.8003 and earlier</ProductID>
            <ProductID>P-8480V-3.2.1182 and earlier</ProductID>
            <ProductID>P-8480V-3.3.2.1162 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="269" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3731</Title>
      <Notes>
         <Note Audience="All" Ordinal="269" Title="Details" Type="Details">Vulnerability in the Secure Global Desktop component of Oracle Virtualization (subcomponent: Core (OpenSSL)).  Supported versions that are affected are 4.71, 5.2 and  5.3. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise Secure Global Desktop.  Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Secure Global Desktop. CVSS 3.0 Base Score 5.9 (Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3731</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.2</ProductID>
            <ProductID>P-8539V-5.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8539V-4.71</ProductID>
            <ProductID>P-8539V-5.2</ProductID>
            <ProductID>P-8539V-5.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="270" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3732</Title>
      <Notes>
         <Note Audience="All" Ordinal="270" Title="Details" Type="Details">Vulnerability in the Oracle Communications Security Gateway component of Oracle Communications Applications (subcomponent: Routing (OpenSSL)).   The supported version that is affected is 3.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Oracle Communications Security Gateway.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Oracle Communications Security Gateway accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3732</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10755V-3.0.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10755V-3.0.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="271" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3732</Title>
      <Notes>
         <Note Audience="All" Ordinal="271" Title="Details" Type="Details">Vulnerability in the MySQL Enterprise Backup component of Oracle MySQL (subcomponent: Backup: ENTRBACK (OpenSSL)).  Supported versions that are affected are 3.12.3 and earlier and  
4.0.3 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Backup.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all MySQL Enterprise Backup accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3732</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4629V-3.12.3 and earlier</ProductID>
            <ProductID>P-4629V-4.0.3 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-4629V-3.12.3 and earlier</ProductID>
            <ProductID>P-4629V-4.0.3 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="272" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-3732</Title>
      <Notes>
         <Note Audience="All" Ordinal="272" Title="Details" Type="Details">Vulnerability in the Primavera P6 Enterprise Project Portfolio Management component of Oracle Primavera Products Suite (subcomponent: Project Manager (OpenSSL)).  Supported versions that are affected are 8.3, 8.4, 15.1, 15.2, 16.1 and  16.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Primavera P6 Enterprise Project Portfolio Management.  Successful attacks of this vulnerability can result in  unauthorized access to critical data or complete access to all Primavera P6 Enterprise Project Portfolio Management accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-3732</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5580V-8.3</ProductID>
            <ProductID>P-5580V-8.4</ProductID>
            <ProductID>P-5580V-15.1</ProductID>
            <ProductID>P-5580V-15.2</ProductID>
            <ProductID>P-5580V-16.1</ProductID>
            <ProductID>P-5580V-16.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  5.9</BaseScore>
            <Vector>AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5580V-8.3</ProductID>
            <ProductID>P-5580V-8.4</ProductID>
            <ProductID>P-5580V-15.1</ProductID>
            <ProductID>P-5580V-15.2</ProductID>
            <ProductID>P-5580V-16.1</ProductID>
            <ProductID>P-5580V-16.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="273" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="273" Title="Details" Type="Details">Vulnerability in the Oracle Communications Policy Management component of Oracle Communications Applications (subcomponent: Security (Struts 2)).   The supported version that is affected is 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Policy Management.  While the vulnerability is in Oracle Communications Policy Management, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Communications Policy Management. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10900V-12.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10900V-12.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="274" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="274" Title="Details" Type="Details">Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).  Supported versions that are affected are 12.0.1, 12.0.2, 12.0.3 and  12.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle FLEXCUBE Private Banking.  While the vulnerability is in Oracle FLEXCUBE Private Banking, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle FLEXCUBE Private Banking. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9110V-12.0.1</ProductID>
            <ProductID>P-9110V-12.0.2</ProductID>
            <ProductID>P-9110V-12.0.3</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9110V-12.0.1</ProductID>
            <ProductID>P-9110V-12.0.2</ProductID>
            <ProductID>P-9110V-12.0.3</ProductID>
            <ProductID>P-9110V-12.1.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="275" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="275" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Analytical Applications Infrastructure component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).  Supported versions that are affected are 7.3.3, 7.3.4 and 7.3.5. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Analytical Applications Infrastructure.  While the vulnerability is in Oracle Financial Services Analytical Applications Infrastructure, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Analytical Applications Infrastructure. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5680V-7.3.3</ProductID>
            <ProductID>P-5680V-7.3.4</ProductID>
            <ProductID>P-5680V-7.3.5</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5680V-7.3.3</ProductID>
            <ProductID>P-5680V-7.3.4</ProductID>
            <ProductID>P-5680V-7.3.5</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="276" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="276" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Reconciliation Framework component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).  Supported versions that are affected are 8.0.0, 8.0.1 and  8.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Reconciliation Framework.  While the vulnerability is in Oracle Financial Services Reconciliation Framework, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Reconciliation Framework. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5748V-8.0.0</ProductID>
            <ProductID>P-5748V-8.0.1</ProductID>
            <ProductID>P-5748V-8.0.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5748V-8.0.0</ProductID>
            <ProductID>P-5748V-8.0.1</ProductID>
            <ProductID>P-5748V-8.0.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="277" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="277" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Asset Liability Management component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).  Supported versions that are affected are 6.0.0, 6.1.0, 6.1.1, 8.0.1, 8.0.2, 8.0.3 and  8.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Asset Liability Management.  While the vulnerability is in Oracle Financial Services Asset Liability Management, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Asset Liability Management. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5662V-6.0.0</ProductID>
            <ProductID>P-5662V-6.1.0</ProductID>
            <ProductID>P-5662V-6.1.1</ProductID>
            <ProductID>P-5662V-8.0.1</ProductID>
            <ProductID>P-5662V-8.0.2</ProductID>
            <ProductID>P-5662V-8.0.3</ProductID>
            <ProductID>P-5662V-8.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5662V-6.0.0</ProductID>
            <ProductID>P-5662V-6.1.0</ProductID>
            <ProductID>P-5662V-6.1.1</ProductID>
            <ProductID>P-5662V-8.0.1</ProductID>
            <ProductID>P-5662V-8.0.2</ProductID>
            <ProductID>P-5662V-8.0.3</ProductID>
            <ProductID>P-5662V-8.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="278" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="278" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Basel Regulatory Capital Basic component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).  Supported versions that are affected are 6.1.2, 6.1.3, 8.0.2 and 8.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Basel Regulatory Capital Basic.  While the vulnerability is in Oracle Financial Services Basel Regulatory Capital Basic, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Basel Regulatory Capital Basic. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9612V-6.1.2</ProductID>
            <ProductID>P-9612V-6.1.3</ProductID>
            <ProductID>P-9612V-8.0.2</ProductID>
            <ProductID>P-9612V-8.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9612V-6.1.2</ProductID>
            <ProductID>P-9612V-6.1.3</ProductID>
            <ProductID>P-9612V-8.0.2</ProductID>
            <ProductID>P-9612V-8.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="279" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="279" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).  Supported versions that are affected are 6.1.2, 6.1.3, 8.0.2 and 8.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach.  While the vulnerability is in Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Basel Regulatory Capital Internal Ratings Based Approach. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9450V-6.1.2</ProductID>
            <ProductID>P-9450V-6.1.3</ProductID>
            <ProductID>P-9450V-8.0.2</ProductID>
            <ProductID>P-9450V-8.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9450V-6.1.2</ProductID>
            <ProductID>P-9450V-6.1.3</ProductID>
            <ProductID>P-9450V-8.0.2</ProductID>
            <ProductID>P-9450V-8.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="280" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="280" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Data Foundation component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).  Supported versions that are affected are 8.0.1, 8.0.2,8.0.3 and  8.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Data Foundation.  While the vulnerability is in Oracle Financial Services Data Foundation, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Data Foundation. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9180V-8.0.1</ProductID>
            <ProductID>P-9180V-8.0.2</ProductID>
            <ProductID>P-9180V-8.0.3</ProductID>
            <ProductID>P-9180V-8.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9180V-8.0.1</ProductID>
            <ProductID>P-9180V-8.0.2</ProductID>
            <ProductID>P-9180V-8.0.3</ProductID>
            <ProductID>P-9180V-8.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="281" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="281" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Data Integration Hub component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).  Supported versions that are affected are 8.0.1, 8.0.2,8.0.3 and  8.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Data Integration Hub.  While the vulnerability is in Oracle Financial Services Data Integration Hub, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Data Integration Hub. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11289V-8.0.1</ProductID>
            <ProductID>P-11289V-8.0.2</ProductID>
            <ProductID>P-11289V-8.0.3</ProductID>
            <ProductID>P-11289V-8.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-11289V-8.0.1</ProductID>
            <ProductID>P-11289V-8.0.2</ProductID>
            <ProductID>P-11289V-8.0.3</ProductID>
            <ProductID>P-11289V-8.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="282" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="282" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Enterprise Financial Performance Analytics component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).   The supported version that is affected is 8.0.0 to 8.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Enterprise Financial Performance Analytics.  While the vulnerability is in Oracle Financial Services Enterprise Financial Performance Analytics, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Enterprise Financial Performance Analytics. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4279V-8.0.0 to 8.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-4279V-8.0.0 to 8.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="283" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="283" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Funds Transfer Pricing component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).  Supported versions that are affected are 6.0.0, 6.1.0, 6.1.1, 8.0.1, 8.0.2, 8.0.3 and  8.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Funds Transfer Pricing.  While the vulnerability is in Oracle Financial Services Funds Transfer Pricing, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Funds Transfer Pricing. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5659V-6.0.0</ProductID>
            <ProductID>P-5659V-6.1.0</ProductID>
            <ProductID>P-5659V-6.1.1</ProductID>
            <ProductID>P-5659V-8.0.1</ProductID>
            <ProductID>P-5659V-8.0.2</ProductID>
            <ProductID>P-5659V-8.0.3</ProductID>
            <ProductID>P-5659V-8.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5659V-6.0.0</ProductID>
            <ProductID>P-5659V-6.1.0</ProductID>
            <ProductID>P-5659V-6.1.1</ProductID>
            <ProductID>P-5659V-8.0.1</ProductID>
            <ProductID>P-5659V-8.0.2</ProductID>
            <ProductID>P-5659V-8.0.3</ProductID>
            <ProductID>P-5659V-8.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="284" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="284" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Hedge Management and IFRS Valuations component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).  Supported versions that are affected are 6.1.1, 8.0.1, 8.0.2, 8.0.3 and  8.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Hedge Management and IFRS Valuations.  While the vulnerability is in Oracle Financial Services Hedge Management and IFRS Valuations, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Hedge Management and IFRS Valuations. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9332V-6.1.1</ProductID>
            <ProductID>P-9332V-8.0.1</ProductID>
            <ProductID>P-9332V-8.0.2</ProductID>
            <ProductID>P-9332V-8.0.3</ProductID>
            <ProductID>P-9332V-8.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9332V-6.1.1</ProductID>
            <ProductID>P-9332V-8.0.1</ProductID>
            <ProductID>P-9332V-8.0.2</ProductID>
            <ProductID>P-9332V-8.0.3</ProductID>
            <ProductID>P-9332V-8.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="285" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="285" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Institutional Performance Analytics component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).   The supported version that is affected is 8.0.0 to 8.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Institutional Performance Analytics.  While the vulnerability is in Oracle Financial Services Institutional Performance Analytics, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Institutional Performance Analytics. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10215V-8.0.0 to 8.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10215V-8.0.0 to 8.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="286" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="286" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Liquidity Risk Management component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).  Supported versions that are affected are 8.0.1, 8.0.2 and  8.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Liquidity Risk Management.  While the vulnerability is in Oracle Financial Services Liquidity Risk Management, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Liquidity Risk Management. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9096V-8.0.1</ProductID>
            <ProductID>P-9096V-8.0.2</ProductID>
            <ProductID>P-9096V-8.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9096V-8.0.1</ProductID>
            <ProductID>P-9096V-8.0.2</ProductID>
            <ProductID>P-9096V-8.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="287" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="287" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Loan Loss Forecasting and Provisioning component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).  Supported versions that are affected are 1.5.0, 1.5.1, 8.0.1, 8.0.2, 8.0.3 and  8.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Loan Loss Forecasting and Provisioning.  While the vulnerability is in Oracle Financial Services Loan Loss Forecasting and Provisioning, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Loan Loss Forecasting and Provisioning. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9474V-1.5.0</ProductID>
            <ProductID>P-9474V-1.5.1</ProductID>
            <ProductID>P-9474V-8.0.1</ProductID>
            <ProductID>P-9474V-8.0.2</ProductID>
            <ProductID>P-9474V-8.0.3</ProductID>
            <ProductID>P-9474V-8.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9474V-1.5.0</ProductID>
            <ProductID>P-9474V-1.5.1</ProductID>
            <ProductID>P-9474V-8.0.1</ProductID>
            <ProductID>P-9474V-8.0.2</ProductID>
            <ProductID>P-9474V-8.0.3</ProductID>
            <ProductID>P-9474V-8.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="288" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="288" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Pricing Management/Transfer Pricing Component component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).   The supported version that is affected is 8.0.0 to 8.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Pricing Management/Transfer Pricing Component.  While the vulnerability is in Oracle Financial Services Pricing Management/Transfer Pricing Component, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Pricing Management/Transfer Pricing Component. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5749V-8.0.0 to 8.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5749V-8.0.0 to 8.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="289" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="289" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Profitability Management component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).  Supported versions that are affected are 6.0.0, 6.1.0, 6.1.1, 8.0.1, 8.0.2, 8.0.3 and  8.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Profitability Management.  While the vulnerability is in Oracle Financial Services Profitability Management, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Profitability Management. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5658V-6.0.0</ProductID>
            <ProductID>P-5658V-6.1.0</ProductID>
            <ProductID>P-5658V-6.1.1</ProductID>
            <ProductID>P-5658V-8.0.1</ProductID>
            <ProductID>P-5658V-8.0.2</ProductID>
            <ProductID>P-5658V-8.0.3</ProductID>
            <ProductID>P-5658V-8.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5658V-6.0.0</ProductID>
            <ProductID>P-5658V-6.1.0</ProductID>
            <ProductID>P-5658V-6.1.1</ProductID>
            <ProductID>P-5658V-8.0.1</ProductID>
            <ProductID>P-5658V-8.0.2</ProductID>
            <ProductID>P-5658V-8.0.3</ProductID>
            <ProductID>P-5658V-8.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="290" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="290" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Retail Customer Analytics component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).   The supported version that is affected is 8.0.0 to 8.0.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Retail Customer Analytics.  While the vulnerability is in Oracle Financial Services Retail Customer Analytics, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Retail Customer Analytics. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10214V-8.0.0 to 8.0.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10214V-8.0.0 to 8.0.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="291" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="291" Title="Details" Type="Details">Vulnerability in the Oracle Financial Services Retail Performance Analytics component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).   The supported version that is affected is 8.0.0 to 8.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Financial Services Retail Performance Analytics.  While the vulnerability is in Oracle Financial Services Retail Performance Analytics, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Financial Services Retail Performance Analytics. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-10216V-8.0.0 to 8.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-10216V-8.0.0 to 8.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="292" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="292" Title="Details" Type="Details">Vulnerability in the Oracle Insurance Data Foundation component of Oracle Financial Services Applications (subcomponent: Core (Struts 2)).  Supported versions that are affected are 8.0.1, 8.0.2,8.0.3 and  8.0.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Insurance Data Foundation.  While the vulnerability is in Oracle Insurance Data Foundation, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Insurance Data Foundation. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9755V-8.0.1</ProductID>
            <ProductID>P-9755V-8.0.2</ProductID>
            <ProductID>P-9755V-8.0.3</ProductID>
            <ProductID>P-9755V-8.0.4</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9755V-8.0.1</ProductID>
            <ProductID>P-9755V-8.0.2</ProductID>
            <ProductID>P-9755V-8.0.3</ProductID>
            <ProductID>P-9755V-8.0.4</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="293" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="293" Title="Details" Type="Details">Vulnerability in the MySQL Enterprise Monitor component of Oracle MySQL (subcomponent: Monitoring: General (Struts 2)).  Supported versions that are affected are 3.1.6.8003 and earlier, 
3.2.1182 and earlier, 
3.3.2.1162 and earlier and . Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor.  While the vulnerability is in MySQL Enterprise Monitor, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of MySQL Enterprise Monitor. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8480V-3.1.6.8003 and earlier</ProductID>
            <ProductID>P-8480V-3.2.1182 and earlier</ProductID>
            <ProductID>P-8480V-3.3.2.1162 and earlier</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8480V-3.1.6.8003 and earlier</ProductID>
            <ProductID>P-8480V-3.2.1182 and earlier</ProductID>
            <ProductID>P-8480V-3.3.2.1162 and earlier</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="294" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="294" Title="Details" Type="Details">Vulnerability in the Siebel Apps - E-Billing component of Oracle Siebel CRM (subcomponent: Security (Struts 2)).  Supported versions that are affected are 6.1, 6.2, 7.0 and  7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel Apps - E-Billing.  While the vulnerability is in Siebel Apps - E-Billing, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Siebel Apps - E-Billing. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8969V-6.1</ProductID>
            <ProductID>P-8969V-6.2</ProductID>
            <ProductID>P-8969V-7.0</ProductID>
            <ProductID>P-8969V-7.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-8969V-6.1</ProductID>
            <ProductID>P-8969V-6.2</ProductID>
            <ProductID>P-8969V-7.0</ProductID>
            <ProductID>P-8969V-7.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="295" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="295" Title="Details" Type="Details">Vulnerability in the Oracle WebCenter Sites component of Oracle Fusion Middleware (subcomponent: Third Party Tools (Struts 2)).  Supported versions that are affected are 11.1.1.8.0, 12.2.1.0.0, 12.2.1.1.0 and  12.2.1.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebCenter Sites.  While the vulnerability is in Oracle WebCenter Sites, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle WebCenter Sites.  Note: The fix for CVE-2017-5638 also addresses CVE-2016-4436. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-9617V-11.1.1.8.0</ProductID>
            <ProductID>P-9617V-12.2.1.0.0</ProductID>
            <ProductID>P-9617V-12.2.1.1.0</ProductID>
            <ProductID>P-9617V-12.2.1.2.0</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="296" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="296" Title="Details" Type="Details">Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Samples (Struts 2)).  Supported versions that are affected are 10.3.6.0, 12.1.3.0, 12.2.1.0, 12.2.1.1 and  12.2.1.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle WebLogic Server.  Successful attacks of this vulnerability can result in takeover of Oracle WebLogic Server. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.0</ProductID>
            <ProductID>P-5242V-12.2.1.1</ProductID>
            <ProductID>P-5242V-12.2.1.2</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>  9.8</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-5242V-10.3.6.0</ProductID>
            <ProductID>P-5242V-12.1.3.0</ProductID>
            <ProductID>P-5242V-12.2.1.0</ProductID>
            <ProductID>P-5242V-12.2.1.1</ProductID>
            <ProductID>P-5242V-12.2.1.2</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="297" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2017-5638</Title>
      <Notes>
         <Note Audience="All" Ordinal="297" Title="Details" Type="Details">Vulnerability in the Oracle Retail XBRi Loss Prevention component of Oracle Retail Applications (subcomponent: Internal Operations (Struts 2)).  Supported versions that are affected are 10.0.1, 10.5.0, 10.6.0, 10.7.0, 10.8.0 and  10.8.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Retail XBRi Loss Prevention.  While the vulnerability is in Oracle Retail XBRi Loss Prevention, attacks may significantly impact additional products.  Successful attacks of this vulnerability can result in takeover of Oracle Retail XBRi Loss Prevention. CVSS 3.0 Base Score 10.0 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2017-5638</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-11506V-10.0.1</ProductID>
            <ProductID>P-11506V-10.5.0</ProductID>
            <ProductID>P-11506V-10.6.0</ProductID>
            <ProductID>P-11506V-10.7.0</ProductID>
            <ProductID>P-11506V-10.8.0</ProductID>
            <ProductID>P-11506V-10.8.1</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore> 10.0</BaseScore>
            <Vector>AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CPUApr2017</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html</URL>
            <ProductID>P-11506V-10.0.1</ProductID>
            <ProductID>P-11506V-10.5.0</ProductID>
            <ProductID>P-11506V-10.6.0</ProductID>
            <ProductID>P-11506V-10.7.0</ProductID>
            <ProductID>P-11506V-10.8.0</ProductID>
            <ProductID>P-11506V-10.8.1</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
</cvrf:cvrfdoc>
