Oracle
Oracle Enterprise Manager: vulnerabilidades y CVE
Oracle Enterprise Manager tiene 34 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE34
Últimos 12 meses1
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-83068 | Alta (7.7) | 0.34% | — | 15 sept 2026 | Vulnerability in the Oracle Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: Core). The supported version that is affected is 24.1. Easily exploitable vulnerability allows low… |
| CVE-2024-20916 | Alta (8.3) | 0.34% | — | 16 ene 2024 | Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Management). The supported version that is affected is 13.5.0.0. Easily exploitable vulnerability… |
| CVE-2021-2134 | Media (6.5) | 0.92% | — | 22 abr 2021 | Vulnerability in the Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: FMW Control Plugin). The supported version that is affected is 12.2.1.4. Easily exploitable vulnerability… |
| CVE-2021-2008 | Alta (7.3) | 0.91% | — | 22 abr 2021 | Vulnerability in the Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: FMW Control Plugin). The supported version that is affected are 11.1.1.9 and 12.2.1.3 Easily exploitable… |
| CVE-2020-2641 | Media (6) | 1.2% | — | 15 ene 2020 | Vulnerability in the Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: Discovery Framework). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily… |
| CVE-2020-2640 | Media (6) | 1.2% | — | 15 ene 2020 | Vulnerability in the Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: Target Management). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily… |
| CVE-2020-2638 | Media (6) | 1.2% | — | 15 ene 2020 | Vulnerability in the Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: Enterprise Config Management). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0.… |
| CVE-2020-2637 | Media (6) | 1.2% | — | 15 ene 2020 | Vulnerability in the Enterprise Manager for Oracle Database product of Oracle Enterprise Manager (component: Change Manager - web based). Supported versions that are affected are 12.1.0.5, 13.2.0.0 and 13.3.0.0. Easily… |
| CVE-2019-2895 | Alta (7.5) | 1.2% | — | 16 oct 2019 | Vulnerability in the Enterprise Manager for Exadata product of Oracle Enterprise Manager (component: Exadata Plug-In Deploy and Ins). Supported versions that are affected are 12.1.0.5.0, 13.2.2.0.0, 13.3.1.0.0 and… |
| CVE-2018-11040 | Alta (7.5) | 3.2% | — | 25 jun 2018 | Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through… |
| CVE-2013-3791 | Media (4.3) | 1.4% | — | 17 jul 2013 | Unspecified vulnerability in Enterprise Manager (EM) Base Platform 10.2.0.5 and EM DB Control 11.1.0.7 in Oracle Enterprise Manager Grid Control allows remote attackers to affect integrity via unknown vectors related to… |
| CVE-2013-3758 | Media (4.3) | 1.2% | — | 17 jul 2013 | Unspecified vulnerability in the Enterprise Manager (EM) Base Platform 10.2.0.5 and 11.1.0.1; EM DB Control 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3; and EM Plugin for DB 12.1.0.2 and 12.1.0.3 in Oracle… |
| CVE-2009-1967 | Media (5.5) | 1.2% | — | 14 jul 2009 | Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2) Oracle Enterprise Manager 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via… |
| CVE-2009-1966 | Media (5.5) | 1.2% | — | 14 jul 2009 | Unspecified vulnerability in the Config Management component in (1) Oracle Database 11.1.0.7 and (2) Oracle Enterprise Manager 10.2.0.4 allows remote authenticated users to affect confidentiality and integrity via… |
| CVE-2008-2603 | Baja (3.5) | 1.2% | — | 15 jul 2008 | Unspecified vulnerability in the Resource Manager component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6, and Database Control in Enterprise Manager, has unknown impact and remote authenticated attack vectors.… |
| CVE-2007-5531 | Alta (10) | 3.6% | — | 17 oct 2007 | Unspecified vulnerability in Oracle Help for Web, as used in Oracle Application Server, Oracle Database 10.2.0.3, and Enterprise Manager 10.1.0.6, has unknown impact and remote attack vectors, aka EM02. |
| CVE-2007-2129 | Alta (10) | 2.2% | — | 18 abr 2007 | Unspecified vulnerability in the Agent component in Oracle Enterprise Manager 9.2.0.8 has unknown impact and remote attack vectors, aka EM01. |
| CVE-2007-0293 | Media (6.4) | 2.1% | — | 17 ene 2007 | Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 and 10.2.0.1 have unknown impact and attack vectors related to (1) Oracle Agent (EM03) and (2) EM04 and (3) EM05 in Enterprise Manager Console.… |
| CVE-2007-0292 | Alta (7.5) | 2.5% | — | 17 ene 2007 | Multiple unspecified vulnerabilities in Oracle Enterprise Manager 10.1.0.5 have unknown impact and attack vectors related to Oracle Agent, aka (1) EM01 and (2) EM02. NOTE: EM05 might be related to CVE-2007-0222. |
| CVE-2007-0294 | Baja (1.7) | 0.37% | — | 17 ene 2007 | Unspecified vulnerability in Oracle Enterprise Manager 10.2.0.1 has unknown impact and attack vectors related to Database Cloning & Data Guard Management, aka EM06. |
| CVE-2006-3719 | Media (5.5) | 2.2% | — | 21 jul 2006 | Unspecified vulnerability in CORE: Repository for Oracle Enterprise Manager 9.0.1.0 and 9.2.0.1 has unknown impact and attack vectors, aka Oracle Vuln# EM01. |
| CVE-2006-3720 | Media (5.5) | 2.2% | — | 21 jul 2006 | Unspecified vulnerability in Enterprise Config Management for Oracle Enterprise Manager 10.1.0.3 has unknown impact and attack vectors, aka Oracle Vuln# EM02. |
| CVE-2006-3721 | Alta (10) | 4.1% | — | 21 jul 2006 | Multiple unspecified vulnerabilities in Oracle Management Service for Oracle Enterprise Manager 10.1.0.5 and 10.2.0.1 have unknown impact and attack vectors, aka Oracle Vuln# EM03 and EM04. |
| CVE-2006-1885 | Alta (10) | 3.9% | — | 20 abr 2006 | Multiple unspecified vulnerabilities in the Reporting Framework component in Oracle Enterprise Manager 9.0.1.5 and 9.2.0.7 have unknown impact and attack vectors, aka Vuln# (1) EM01 and (2) EM02. |
| CVE-2004-1366 | Media (4.6) | 15% | — | 4 ago 2004 | Oracle 10g Database Server stores the password for the SYSMAN account in cleartext in the world-readable emoms.properties file, which could allow local users to gain DBA privileges. |
| CVE-2004-1367 | Media (4.4) | 7.3% | — | 4 ago 2004 | Oracle 10g Database Server, when installed with a password that contains an exclamation point ("!") for the (1) DBSNMP or (2) SYSMAN user, generates an error that logs the password in the world-readable… |
| CVE-2004-1362 | Alta (7.5) | 9.0% | — | 4 ago 2004 | The PL/SQL module for the Oracle HTTP Server in Oracle Application Server 10g, when using the WE8ISO8859P1 character set, does not perform character conversions properly, which allows remote attackers to bypass access… |
| CVE-2004-1370 | Alta (7.5) | 3.9% | — | 4 ago 2004 | Multiple SQL injection vulnerabilities in PL/SQL procedures that run with definer rights in Oracle 9i and 10g allow remote attackers to execute arbitrary SQL commands and gain privileges via (1) DBMS_EXPORT_EXTENSION,… |
| CVE-2004-1365 | Media (4.6) | 7.4% | — | 4 ago 2004 | Extproc in Oracle 9i and 10g does not require authentication to load a library or execute a function, which allows local users to execute arbitrary commands as the Oracle user. |
| CVE-2004-1369 | Media (5) | 5.6% | — | 4 ago 2004 | The TNS Listener in Oracle 10g allows remote attackers to cause a denial of service (listener crash) via a malformed service_register_NSGR request containing a value that is used as an invalid offset for a pointer that… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.