Oracle
Oracle Agile Engineering Data Management: vulnerabilidades y CVE
Oracle Agile Engineering Data Management tiene 49 vulnerabilidades publicadas, 19 de ellas en los últimos 12 meses. 4 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE49
Últimos 12 meses19
Críticas4
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2016-8735 | Crítica (9.8) | 90% | ⚠ Explotación activa | 6 abr 2017 | Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX… |
| CVE-2020-1938 | Crítica (9.8) | 99% | ⚠ Explotación activa | 24 feb 2020 | When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-87262 | Alta (7.1) | 0.24% | — | 15 sept 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable… |
| CVE-2026-87261 | Alta (7.3) | 0.14% | — | 15 sept 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable… |
| CVE-2026-87260 | Alta (7.3) | 0.23% | — | 15 sept 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable… |
| CVE-2026-87259 | Alta (8.4) | 0.14% | — | 15 sept 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Easily exploitable… |
| CVE-2026-71053 | Alta (8.1) | 0.39% | — | 18 ago 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Web Services Security). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows… |
| CVE-2026-71052 | Alta (8.8) | 0.43% | — | 18 ago 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Web Services Security). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows… |
| CVE-2026-70712 | Media (6.4) | 0.15% | — | 18 ago 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows high… |
| CVE-2026-70698 | Media (6.7) | 0.18% | — | 18 ago 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows high privileged… |
| CVE-2026-70697 | Alta (7) | 0.13% | — | 18 ago 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit… |
| CVE-2026-70693 | Media (6.3) | 0.14% | — | 18 ago 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit… |
| CVE-2026-70691 | Alta (7.5) | 0.33% | — | 18 ago 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Communication Interface). The supported version that is affected is 6.2.1. Difficult to exploit… |
| CVE-2026-61195 | Media (6.5) | 0.42% | — | 21 jul 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged… |
| CVE-2026-61194 | Media (6.5) | 0.42% | — | 21 jul 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Core). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged… |
| CVE-2026-61192 | Media (5.3) | 0.34% | — | 21 jul 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low… |
| CVE-2026-61191 | Media (4.4) | 0.14% | — | 21 jul 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Document Management). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low… |
| CVE-2026-61190 | Media (6.4) | 0.26% | — | 21 jul 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Difficult to exploit vulnerability allows low… |
| CVE-2026-61189 | Media (6.5) | 0.15% | — | 21 jul 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged… |
| CVE-2026-61187 | Baja (2.8) | 0.14% | — | 21 jul 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows low privileged… |
| CVE-2026-61186 | Crítica (9.4) | 0.41% | — | 21 jul 2026 | Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Install). The supported version that is affected is 6.2.1. Easily exploitable vulnerability allows unauthenticated… |
| CVE-2022-23181 | Alta (7) | 0.69% | — | 27 ene 2022 | The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to… |
| CVE-2022-23437 | Media (6.5) | 12% | — | 24 ene 2022 | There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an infinite loop, which may sometimes… |
| CVE-2021-45105 | Media (5.9) | 100% | — | 18 dic 2021 | Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data… |
| CVE-2021-42340 | Alta (7.5) | 12% | — | 14 oct 2021 | The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade… |
| CVE-2021-2351 | Alta (7.5) | 2.4% | — | 21 jul 2021 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated… |
| CVE-2021-36374 | Media (5.5) | 2.6% | — | 14 jul 2021 | When reading a specially crafted ZIP archive, or a derived formats, an Apache Ant build can be made to allocate large amounts of memory that leads to an out of memory error, even for small inputs. This can be used to… |
| CVE-2021-29425 | Media (4.8) | 9.9% | — | 13 abr 2021 | In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to… |
| CVE-2020-11987 | Alta (8.2) | 13% | — | 24 feb 2021 | Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause… |
| CVE-2021-1996 | Baja (2.4) | 1.3% | — | 20 ene 2021 | Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows high… |
| CVE-2020-17521 | Media (5.5) | 1.0% | — | 7 dic 2020 | Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now superseded Java JDK method call that is… |
| CVE-2020-11979 | Alta (7.5) | 8.0% | — | 1 oct 2020 | As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.