Known Vulnerabilities for Enterprise Manager For Virtualization by Oracle
Listed below are 8 of the newest known vulnerabilities associated with "Enterprise Manager For Virtualization" by "Oracle".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-10086 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an att... | 7.3 - HIGH | 2019-08-20 | 2023-11-07 |
| CVE-2018-14721 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attack... | 10 - CRITICAL | 2019-01-02 | 2023-11-07 |
| CVE-2018-14720 | FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging ... | 9.8 - CRITICAL | 2019-01-02 | 2023-11-07 |
| CVE-2018-14719 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to b... | 9.8 - CRITICAL | 2019-01-02 | 2023-11-07 |
| CVE-2018-14718 | FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to b... | 9.8 - CRITICAL | 2019-01-02 | 2023-11-07 |
| CVE-2017-15707 | In Apache Struts 2.5 to 2.5.14, the REST Plugin is using an outdated JSON-lib library which is vulnerable and allow perform a... | 6.2 - MEDIUM | 2017-12-01 | 2019-04-26 |
| CVE-2017-15095 | A deserialization flaw was discovered in the jackson-databind in versions before 2.8.10 and 2.9.1, which could allow an unaut... | 9.8 - CRITICAL | 2018-02-06 | 2023-11-07 |
| CVE-2017-7525 | A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow ... | 9.8 - CRITICAL | 2018-02-06 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Enterprise Manager For Virtualization | 13.3.1 | All | All | All |
| Application | Oracle | Enterprise Manager For Virtualization | 13.2.3 | All | All | All |
| Application | Oracle | Enterprise Manager For Virtualization | 13.2.2 | All | All | All |