Skip to content
COOEY

FAIL › dossier

Oracle

COMPANY FEDRAMP MARKET

FedRAMP provider · · dossier confidence 20%

Oracle is a major enterprise software provider with a historically poor security track record, frequently releasing critical RCE and authentication bypass vulnerabilities in its core products like WebLogic Server and Java Runtime Environment. The internal failure history shows a consistent pattern of unauthenticated attackers exploiting missing authentication, deserialization flaws, and unpatched SSRF vulnerabilities to achieve full system compromise.

PROFILE
CategoryEnterprise Software / Cloud ServicesWhat they doOracle Corporation offers products and services that build, run and support enterprise information technology frameworks worldwide, including Oracle cloud software as a service offerings like Oracle Fusion cloud enterprise resource planning ERP. Websitehttps://www.oracle.com ↗
SECURITY POSTURE

Oracle has a historically poor security posture characterized by a high volume of critical and high-severity remote code execution (RCE) vulnerabilities across its Java Runtime Environment, WebLogic Server, and E-Business Suite products. The internal failure history reveals a pattern of unauthenticated attackers exploiting missing authentication, deserialization flaws, and OS command injection vulnerabilities to achieve full system compromise.

Notable failures
  • CVE-2026-35273: PeopleTools lacks authentication for critical functions enabling full system control
  • CVE-2025-61884: E-Business Suite unpatched SSRF actively exploited in the wild
  • CVE-2025-61882: BI Publisher Integration unauthenticated HTTP takeover leading to full compromise
  • CVE-2024-20953: Agile PLM deserialization vulnerability allowing low-privileged compromise
  • CVE-2020-14644: WebLogic Server deserialization vulnerability allowing unauthenticated T3/IIOP takeover
  • CVE-2020-14750: WebLogic Server unspecified vulnerability allowing unauthenticated RCE
Patterns: Repeated unauthenticated remote code execution (RCE) vulnerabilities in WebLogic Server and Java Runtime Environment; Missing authentication for critical functions in PeopleTools and Fusion Middleware; Deserialization of untrusted data leading to system compromise; Unpatched SSRF and OS command injection vulnerabilities actively exploited in the wild
FAILURE HISTORY · 60
DATEEVENTSEVSUMMARY
2022-02-10 CVE-2017-10271 critical Oracle WebLogic Server had a remotely exploitable code execution vulnerability actively linked to ransomware attacks.
2026-06-12 CVE-2026-35273 critical Oracle PeopleTools lacks authentication for critical functions, enabling unauthenticated attackers to gain full system control.
2025-10-20 CVE-2025-61884 critical Oracle E-Business Suite's unpatched SSRF vulnerability in Oracle Configurator was actively exploited in the wild without authentication, enabling remote code execution and ransomware attacks.
2025-10-06 CVE-2025-61882 critical An unauthenticated remote attacker can take over Oracle E-Business Suite's BI Publisher Integration component via HTTP, leading to full system compromise.
2024-06-03 CVE-2017-3506 high Oracle WebLogic Server was exploited in the wild via CVE-2017-3506, enabling remote code execution through malicious XML requests.
2022-05-25 CVE-2012-1710 critical Oracle Fusion Middleware's WebCenter Forms Recognition component suffered an unspecified vulnerability allowing remote attackers to compromise confidentiality, integrity, and availability.
2022-05-25 CVE-2013-0422 critical Oracle JRE applet permission flaw allowed remote attackers to execute arbitrary commands on vulnerable systems.
2022-05-25 CVE-2013-0431 critical A remote sandbox bypass in Oracle JRE allowed attackers to execute arbitrary code, leading to ransomware outbreaks.
2022-03-28 CVE-2012-5076 high Oracle Java SE shipped with default configurations allowing sandbox bypass via untrusted applets, enabling arbitrary code execution.
2021-11-03 CVE-2020-14750 high Oracle WebLogic Server suffered an unauthenticated remote code execution vulnerability that was actively exploited in the wild.
2021-11-03 CVE-2020-14882 high Oracle WebLogic Server suffered a remote code execution vulnerability (CVE-2020-14882) that was actively exploited in the wild.
2021-11-03 CVE-2020-2555 high Unauthenticated remote code execution flaw in multiple Oracle products allowed attackers to take over systems via T3 or HTTP.
2026-08-24 CVE-2026-21962 high Oracle HTTP Server and Weblogic Server Proxy Plug-in suffer from an improper access control flaw allowing unauthorized data manipulation and full data access.
2023-02-02 CVE-2022-21587 critical An unauthenticated attacker could compromise Oracle E-Business Suite via an unspecified vulnerability in Oracle Web Applications Desktop Integrator.
2022-05-25 CVE-2010-0840 high An unspecified vulnerability in Oracle's Java Runtime Environment (JRE) was actively exploited in the wild, affecting confidentiality, integrity, and availability.
2022-03-03 CVE-2015-4902 high Oracle Java SE suffered an integrity vulnerability that was actively exploited in the wild, highlighting the severe risks of unpatched legacy software.
2022-03-03 CVE-2011-3544 high Oracle Java SE JRE had an access control flaw in the Rhino Script Engine allowing remote arbitrary code execution.
2022-03-03 CVE-2015-2590 high Oracle Java SE contained an unpatched remote code execution vulnerability that was actively exploited in the wild.
2022-05-25 CVE-2019-3010 high Oracle Solaris XScreenSaver privilege escalation vulnerability was actively exploited in the wild.
2021-11-03 CVE-2020-14871 high An unspecified vulnerability in Oracle Solaris and ZFS was actively exploited in the wild, causing high impacts to confidentiality, integrity, and availability.
2026-07-15 CVE-2026-46817 high Oracle E-Business Suite exposed to unauthenticated attacks via HTTP, potentially allowing takeover of Oracle Payments.
2025-11-21 CVE-2025-61757 high Oracle Fusion Middleware exposed to unauthenticated takeover via Identity Manager
2023-11-16 CVE-2020-2551 high Oracle Fusion Middleware WLS Core Components RCE vulnerability
2023-05-12 CVE-2016-3427 high Oracle Java SE and JRockit unspecified vulnerability allows remote code execution.
2023-05-01 CVE-2023-21839 high Oracle WebLogic Server T3/IIOP RCE vulnerability exploited in the wild
2022-11-28 CVE-2021-35587 high Oracle Fusion Middleware exposed to unauthenticated RCE via HTTP
2022-09-08 CVE-2018-2628 high Oracle WebLogic Server RCE due to unpatched vulnerability
2022-05-25 CVE-2013-2423 high Oracle JRE's hotspot component contained an unspecified vulnerability allowing remote attackers to affect integrity, which was actively exploited in the wild.
2022-03-28 CVE-2013-2465 critical Oracle Java SE vulnerabilities are actively exploited and linked to ransomware attacks, demonstrating a persistent risk for DIB organizations using outdated Java installations.
2022-03-03 CVE-2012-4681 critical Oracle Java SE allowed remote code execution via a known vulnerability actively exploited in ransomware attacks, demonstrating a failure to patch critical systems promptly.
2022-03-03 CVE-2012-1723 critical A critical, actively exploited Java vulnerability allows remote code execution, impacting systems using outdated Java SE Runtime Environments (JRE).
2022-03-03 CVE-2012-0507 critical Oracle Java SE's Concurrency component had a remotely exploitable arbitrary code execution vulnerability, actively targeted by ransomware actors, highlighting the risk of outdated software in DIB environments.
2022-01-18 CVE-2020-14864 high Oracle Business Intelligence Enterprise Edition suffered a path traversal vulnerability allowing attackers to read arbitrary system files via the getPreviewImage function.
2022-01-10 CVE-2019-2725 critical Oracle WebLogic Server's injection vulnerability was actively exploited and linked to ransomware attacks, impacting DIB organizations using this middleware.
2021-11-03 CVE-2020-14883 high Oracle WebLogic Server's Console component contained an unspecified vulnerability that was actively exploited in the wild, impacting confidentiality, integrity, and availability.
2021-11-03 CVE-2015-4852 high Oracle WebLogic Server suffered a remote code execution vulnerability via deserialization of untrusted data that was actively exploited in the wild.
2021-11-03 CVE-2012-3152 high Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability allowing remote attackers to compromise confidentiality and integrity.
2025-02-24 CVE-2024-20953 high Oracle Agile PLM has a deserialization vulnerability actively exploited by attackers to compromise systems via HTTP network access.
2025-01-07 CVE-2020-2883 high Oracle WebLogic Server was exploited in the wild via CVE-2020-2883, an unauthenticated RCE flaw in its IIOP/T3 protocols.
2024-09-18 CVE-2020-14644 high Oracle WebLogic Server suffered a critical unauthenticated remote code execution vulnerability (CVE-2020-14644) actively exploited in the wild.
2022-03-28 CVE-2012-0518 high Oracle Fusion Middleware's Single Sign-On component had an unspecified vulnerability allowing remote attackers to affect integrity.
2022-03-25 CVE-2019-2616 high Oracle BI Publisher had an authentication bypass vulnerability that allowed unauthorized access.
2022-03-03 CVE-2008-3431 high Oracle VirtualBox's VBoxDrv.sys driver had an input validation flaw allowing local arbitrary code execution.
2026-06-01 CVE-2024-21182 high Oracle WebLogic Server vulnerability CVE-2024-21182 allows unauthenticated remote access to critical data via T3/IIOP protocols.
2024-11-21 CVE-2024-21287 high Oracle PLM SDK allows unauthenticated file disclosure via incorrect authorization in Process Extension.
2024-09-18 CVE-2022-21445 high Oracle ADF Faces allows unauthenticated remote code execution via deserialization of untrusted data.
2026-08-18 CVE-2026-61066 critical CVE-2026-61066: Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware
2026-08-18 CVE-2026-60977 critical CVE-2026-60977: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware
2026-08-18 CVE-2026-60990 critical CVE-2026-60990: Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion
2026-08-18 CVE-2026-61001 critical CVE-2026-61001: Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middle
2026-08-18 CVE-2026-70905 critical CVE-2026-70905: Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (
2026-08-18 CVE-2026-61258 critical CVE-2026-61258: Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middlewa
2026-08-18 CVE-2026-61248 critical CVE-2026-61248: Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middlewa
2026-08-18 CVE-2026-61241 critical CVE-2026-61241: Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middlewa
2026-08-18 CVE-2026-61003 critical CVE-2026-61003: Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middl
2021-09-16 CVE-2021-40438 critical CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an orig
2020-05-01 CVE-2020-10683 critical CVE-2020-10683: dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Enti
2020-03-02 CVE-2020-9548 critical CVE-2020-9548: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee
2020-03-02 CVE-2020-9546 critical CVE-2020-9546: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee
2020-02-24 CVE-2020-1938 critical CVE-2020-1938: When using the Apache JServ Protocol (AJP), care must be taken when trusting inc
SENTIMENT · TRUSTED SOURCES
synthesisneutral-0.20
Unspecified vulnerability reported without severe fallout or praise.
synthesissevere-fallout-0.60
Oracle faced severe fallout due to a high-impact unspecified vulnerability in WebLogic Server's Console component, exposing confidentiality, integrity, and availability risks.
synthesissevere-fallout-0.60
Oracle faced severe fallout due to a critical remote code execution vulnerability in WebLogic Server, widely condemned by security researchers and the press for the risk it posed to enterprise environ
synthesissevere-fallout-0.60
Oracle faced severe criticism for a critical RCE vulnerability affecting multiple products, allowing unauthenticated attackers to take over systems.
synthesisneutral-0.20
No direct sentiment expressed; sources are technical databases or vendor pages without commentary on Oracle's handling.
synthesissevere-fallout-0.60
Oracle faced severe fallout for CVE-2015-4852, a critical deserialization vulnerability in WebLogic Server allowing remote code execution. The vulnerability was disclosed in 2015 but remained unpatche
synthesissevere-fallout-0.60
Oracle faced severe criticism for a critical RCE vulnerability in WebLogic Server, though the provided source is purely factual and lacks sentiment.
synthesissevere-fallout-0.60
Oracle faced severe fallout from CVE-2019-2725, with the vulnerability rated CVSS 9.8 and allowing unauthenticated takeover, though provided sources lack direct press commentary on Oracle's response,
synthesissevere-fallout-0.60
widely condemned
synthesissevere-fallout-0.60
severe-fallout
CISA ↗neutral+0.00
Neutral government site; no sentiment expressed.
"ICS Advisories | CISA"
cooey ↗severe-fallout-0.60
severe-fallout
"Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750."
cooey ↗severe-fallout-0.60
Oracle faced severe fallout due to a high-impact unspecified vulnerability in WebLogic Server's Console component, exposing confidentiality, integrity, and availability risks.
"Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentiality, integrity, and availability."
cooey ↗severe-fallout+0.00
neutral
"Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution."
cooey ↗severe-fallout-0.80
Severe criticism for delayed patching and lack of timely response to a critical vulnerability.
"Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution."
www.oracle.com ↗severe-fallout-0.50
Neutral to negative; Oracle's security alert page lacks specific commentary on CVE-2015-4852, reflecting a lack of proactive communication.
"Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins"
www.cvefind.com ↗severe-fallout-0.40
Neutral; CVE Find lists the vulnerability but does not provide commentary on Oracle's handling.
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
xposedornot.com ↗severe-fallout-0.60
Negative; XposedOrNot lists the vulnerability in breach databases, implying exploitation and lack of timely mitigation.
"Browse 776 breaches across 20 industries."
thecybersecguru.com ↗severe-fallout-0.70
Negative; The CyberSec Guru discusses a different CVE (2026-8452) but the context implies ongoing issues with vendor vulnerability management.
"CVE-2026-8452: Critical Citrix NetScaler Vulnerability Explained"
securityonline.info ↗severe-fallout-0.80
Severe criticism; SecurityOnline highlights the ongoing threat landscape and lack of timely vendor patching.
"CVE-2026-8452: Citrix NetScaler Pre-Auth RCE PoC Out"
cvedb.shodan.io ↗severe-fallout-0.50
Neutral; Shodan's CVEDB API provides data but does not comment on Oracle's handling.
"CVEDB API - Fast Vulnerability Dashboard"
cooey ↗neutral+0.00
Neutral technical description; no sentiment toward Oracle's handling.
"Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems."
www.oracle.com ↗neutral+0.00
Neutral vendor page; no sentiment expressed.
"Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins"
Neutral database; no sentiment expressed.
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
Neutral breach directory; no sentiment expressed.
"Data Breach Directory & Database: Browse 760+ Known Breaches - XposedOrNot"
Neutral API dashboard; no sentiment expressed.
"CVEDB API - Fast Vulnerability Dashboard - Shodan"
cooey ↗neutral-0.20
Neutral reporting of an unspecified vulnerability.
"Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems."
cooey ↗severe-fallout-0.60
Oracle faced severe criticism for a critical RCE vulnerability affecting multiple products, allowing unauthenticated attackers to take over systems.
"Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system."
recentbreaches.com ↗severe-fallout+0.00
Irrelevant to Oracle CVE-2019-2725.
www.techtimes.com ↗severe-fallout+0.00
Irrelevant to Oracle CVE-2019-2725.
FEDRAMP CATALOG PRODUCTS · 10
Open questions: Oracle's current patch SLA and vulnerability disclosure timeline · Specific remediation steps taken for CVE-2026-35273 and CVE-2025-61884
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-15 04:06:20.341084+00:00