FAIL › dossier
Oracle
COMPANY FEDRAMP MARKETFedRAMP provider · · dossier confidence 20%
Oracle is a major enterprise software provider with a historically poor security track record, frequently releasing critical RCE and authentication bypass vulnerabilities in its core products like WebLogic Server and Java Runtime Environment. The internal failure history shows a consistent pattern of unauthenticated attackers exploiting missing authentication, deserialization flaws, and unpatched SSRF vulnerabilities to achieve full system compromise.
Oracle has a historically poor security posture characterized by a high volume of critical and high-severity remote code execution (RCE) vulnerabilities across its Java Runtime Environment, WebLogic Server, and E-Business Suite products. The internal failure history reveals a pattern of unauthenticated attackers exploiting missing authentication, deserialization flaws, and OS command injection vulnerabilities to achieve full system compromise.
- CVE-2026-35273: PeopleTools lacks authentication for critical functions enabling full system control
- CVE-2025-61884: E-Business Suite unpatched SSRF actively exploited in the wild
- CVE-2025-61882: BI Publisher Integration unauthenticated HTTP takeover leading to full compromise
- CVE-2024-20953: Agile PLM deserialization vulnerability allowing low-privileged compromise
- CVE-2020-14644: WebLogic Server deserialization vulnerability allowing unauthenticated T3/IIOP takeover
- CVE-2020-14750: WebLogic Server unspecified vulnerability allowing unauthenticated RCE
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-02-10 | CVE-2017-10271 | critical | Oracle WebLogic Server had a remotely exploitable code execution vulnerability actively linked to ransomware attacks. |
| 2026-06-12 | CVE-2026-35273 | critical | Oracle PeopleTools lacks authentication for critical functions, enabling unauthenticated attackers to gain full system control. |
| 2025-10-20 | CVE-2025-61884 | critical | Oracle E-Business Suite's unpatched SSRF vulnerability in Oracle Configurator was actively exploited in the wild without authentication, enabling remote code execution and ransomware attacks. |
| 2025-10-06 | CVE-2025-61882 | critical | An unauthenticated remote attacker can take over Oracle E-Business Suite's BI Publisher Integration component via HTTP, leading to full system compromise. |
| 2024-06-03 | CVE-2017-3506 | high | Oracle WebLogic Server was exploited in the wild via CVE-2017-3506, enabling remote code execution through malicious XML requests. |
| 2022-05-25 | CVE-2012-1710 | critical | Oracle Fusion Middleware's WebCenter Forms Recognition component suffered an unspecified vulnerability allowing remote attackers to compromise confidentiality, integrity, and availability. |
| 2022-05-25 | CVE-2013-0422 | critical | Oracle JRE applet permission flaw allowed remote attackers to execute arbitrary commands on vulnerable systems. |
| 2022-05-25 | CVE-2013-0431 | critical | A remote sandbox bypass in Oracle JRE allowed attackers to execute arbitrary code, leading to ransomware outbreaks. |
| 2022-03-28 | CVE-2012-5076 | high | Oracle Java SE shipped with default configurations allowing sandbox bypass via untrusted applets, enabling arbitrary code execution. |
| 2021-11-03 | CVE-2020-14750 | high | Oracle WebLogic Server suffered an unauthenticated remote code execution vulnerability that was actively exploited in the wild. |
| 2021-11-03 | CVE-2020-14882 | high | Oracle WebLogic Server suffered a remote code execution vulnerability (CVE-2020-14882) that was actively exploited in the wild. |
| 2021-11-03 | CVE-2020-2555 | high | Unauthenticated remote code execution flaw in multiple Oracle products allowed attackers to take over systems via T3 or HTTP. |
| 2026-08-24 | CVE-2026-21962 | high | Oracle HTTP Server and Weblogic Server Proxy Plug-in suffer from an improper access control flaw allowing unauthorized data manipulation and full data access. |
| 2023-02-02 | CVE-2022-21587 | critical | An unauthenticated attacker could compromise Oracle E-Business Suite via an unspecified vulnerability in Oracle Web Applications Desktop Integrator. |
| 2022-05-25 | CVE-2010-0840 | high | An unspecified vulnerability in Oracle's Java Runtime Environment (JRE) was actively exploited in the wild, affecting confidentiality, integrity, and availability. |
| 2022-03-03 | CVE-2015-4902 | high | Oracle Java SE suffered an integrity vulnerability that was actively exploited in the wild, highlighting the severe risks of unpatched legacy software. |
| 2022-03-03 | CVE-2011-3544 | high | Oracle Java SE JRE had an access control flaw in the Rhino Script Engine allowing remote arbitrary code execution. |
| 2022-03-03 | CVE-2015-2590 | high | Oracle Java SE contained an unpatched remote code execution vulnerability that was actively exploited in the wild. |
| 2022-05-25 | CVE-2019-3010 | high | Oracle Solaris XScreenSaver privilege escalation vulnerability was actively exploited in the wild. |
| 2021-11-03 | CVE-2020-14871 | high | An unspecified vulnerability in Oracle Solaris and ZFS was actively exploited in the wild, causing high impacts to confidentiality, integrity, and availability. |
| 2026-07-15 | CVE-2026-46817 | high | Oracle E-Business Suite exposed to unauthenticated attacks via HTTP, potentially allowing takeover of Oracle Payments. |
| 2025-11-21 | CVE-2025-61757 | high | Oracle Fusion Middleware exposed to unauthenticated takeover via Identity Manager |
| 2023-11-16 | CVE-2020-2551 | high | Oracle Fusion Middleware WLS Core Components RCE vulnerability |
| 2023-05-12 | CVE-2016-3427 | high | Oracle Java SE and JRockit unspecified vulnerability allows remote code execution. |
| 2023-05-01 | CVE-2023-21839 | high | Oracle WebLogic Server T3/IIOP RCE vulnerability exploited in the wild |
| 2022-11-28 | CVE-2021-35587 | high | Oracle Fusion Middleware exposed to unauthenticated RCE via HTTP |
| 2022-09-08 | CVE-2018-2628 | high | Oracle WebLogic Server RCE due to unpatched vulnerability |
| 2022-05-25 | CVE-2013-2423 | high | Oracle JRE's hotspot component contained an unspecified vulnerability allowing remote attackers to affect integrity, which was actively exploited in the wild. |
| 2022-03-28 | CVE-2013-2465 | critical | Oracle Java SE vulnerabilities are actively exploited and linked to ransomware attacks, demonstrating a persistent risk for DIB organizations using outdated Java installations. |
| 2022-03-03 | CVE-2012-4681 | critical | Oracle Java SE allowed remote code execution via a known vulnerability actively exploited in ransomware attacks, demonstrating a failure to patch critical systems promptly. |
| 2022-03-03 | CVE-2012-1723 | critical | A critical, actively exploited Java vulnerability allows remote code execution, impacting systems using outdated Java SE Runtime Environments (JRE). |
| 2022-03-03 | CVE-2012-0507 | critical | Oracle Java SE's Concurrency component had a remotely exploitable arbitrary code execution vulnerability, actively targeted by ransomware actors, highlighting the risk of outdated software in DIB environments. |
| 2022-01-18 | CVE-2020-14864 | high | Oracle Business Intelligence Enterprise Edition suffered a path traversal vulnerability allowing attackers to read arbitrary system files via the getPreviewImage function. |
| 2022-01-10 | CVE-2019-2725 | critical | Oracle WebLogic Server's injection vulnerability was actively exploited and linked to ransomware attacks, impacting DIB organizations using this middleware. |
| 2021-11-03 | CVE-2020-14883 | high | Oracle WebLogic Server's Console component contained an unspecified vulnerability that was actively exploited in the wild, impacting confidentiality, integrity, and availability. |
| 2021-11-03 | CVE-2015-4852 | high | Oracle WebLogic Server suffered a remote code execution vulnerability via deserialization of untrusted data that was actively exploited in the wild. |
| 2021-11-03 | CVE-2012-3152 | high | Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability allowing remote attackers to compromise confidentiality and integrity. |
| 2025-02-24 | CVE-2024-20953 | high | Oracle Agile PLM has a deserialization vulnerability actively exploited by attackers to compromise systems via HTTP network access. |
| 2025-01-07 | CVE-2020-2883 | high | Oracle WebLogic Server was exploited in the wild via CVE-2020-2883, an unauthenticated RCE flaw in its IIOP/T3 protocols. |
| 2024-09-18 | CVE-2020-14644 | high | Oracle WebLogic Server suffered a critical unauthenticated remote code execution vulnerability (CVE-2020-14644) actively exploited in the wild. |
| 2022-03-28 | CVE-2012-0518 | high | Oracle Fusion Middleware's Single Sign-On component had an unspecified vulnerability allowing remote attackers to affect integrity. |
| 2022-03-25 | CVE-2019-2616 | high | Oracle BI Publisher had an authentication bypass vulnerability that allowed unauthorized access. |
| 2022-03-03 | CVE-2008-3431 | high | Oracle VirtualBox's VBoxDrv.sys driver had an input validation flaw allowing local arbitrary code execution. |
| 2026-06-01 | CVE-2024-21182 | high | Oracle WebLogic Server vulnerability CVE-2024-21182 allows unauthenticated remote access to critical data via T3/IIOP protocols. |
| 2024-11-21 | CVE-2024-21287 | high | Oracle PLM SDK allows unauthenticated file disclosure via incorrect authorization in Process Extension. |
| 2024-09-18 | CVE-2022-21445 | high | Oracle ADF Faces allows unauthenticated remote code execution via deserialization of untrusted data. |
| 2026-08-18 | CVE-2026-61066 | critical | CVE-2026-61066: Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware |
| 2026-08-18 | CVE-2026-60977 | critical | CVE-2026-60977: Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware |
| 2026-08-18 | CVE-2026-60990 | critical | CVE-2026-60990: Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion |
| 2026-08-18 | CVE-2026-61001 | critical | CVE-2026-61001: Vulnerability in the Oracle Web Services Manager product of Oracle Fusion Middle |
| 2026-08-18 | CVE-2026-70905 | critical | CVE-2026-70905: Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware ( |
| 2026-08-18 | CVE-2026-61258 | critical | CVE-2026-61258: Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middlewa |
| 2026-08-18 | CVE-2026-61248 | critical | CVE-2026-61248: Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middlewa |
| 2026-08-18 | CVE-2026-61241 | critical | CVE-2026-61241: Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middlewa |
| 2026-08-18 | CVE-2026-61003 | critical | CVE-2026-61003: Vulnerability in the Oracle Managed File Transfer product of Oracle Fusion Middl |
| 2021-09-16 | CVE-2021-40438 | critical | CVE-2021-40438: A crafted request uri-path can cause mod_proxy to forward the request to an orig |
| 2020-05-01 | CVE-2020-10683 | critical | CVE-2020-10683: dom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Enti |
| 2020-03-02 | CVE-2020-9548 | critical | CVE-2020-9548: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee |
| 2020-03-02 | CVE-2020-9546 | critical | CVE-2020-9546: FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee |
| 2020-02-24 | CVE-2020-1938 | critical | CVE-2020-1938: When using the Apache JServ Protocol (AJP), care must be taken when trusting inc |
"Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750."
"Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentiality, integrity, and availability."
"Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution."
"Oracle WebLogic Server contains a deserialization of untrusted data vulnerability within Apache Commons, which can allow for for remote code execution."
"Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins"
"CVE, short for Common Vulnerabilities and Exposures, is a list of publicly disclosed computer security flaws."
"Browse 776 breaches across 20 industries."
"CVE-2026-8452: Critical Citrix NetScaler Vulnerability Explained"
"CVE-2026-8452: Citrix NetScaler Pre-Auth RCE PoC Out"
"CVEDB API - Fast Vulnerability Dashboard"
"Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems."
"Critical Patch Updates, Critical Security Patch Updates, Security Alerts and Bulletins"
"Database CVE, CWE, CISA KEV & Vulnerability Intelligence | CVE Find"
"Data Breach Directory & Database: Browse 760+ Known Breaches - XposedOrNot"
"CVEDB API - Fast Vulnerability Dashboard - Shodan"
"Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability that allows remote attackers to affect confidentiality and integrity of affected systems."
"Multiple Oracle products contain a remote code execution vulnerability that allows an unauthenticated attacker with network access via T3 or HTTP to takeover the affected system."
| PRODUCT | STATUS | IMPACT |
|---|---|---|
| Aconex for Defense | Authorized | Moderate |
| Federal Managed Cloud Services | Authorized | Moderate |
| Fusion Cloud | Authorized | Moderate |
| Government Cloud - Common Controls | Authorized | High |
| Oracle Cloud Infrastructure-Government Cloud | Authorized | High |
| Oracle Enterprise Performance Management (EPM) | Authorized | Low |
| Oracle Enterprise Performance Management (EPM) - Moderate | In Process | Moderate |
| Oracle Service Cloud | Authorized | Moderate |
| Oracle Service Cloud (DOD) | Authorized | Moderate |
| Taleo Cloud - U.S. Government Cloud | Authorized | Moderate |
- Oracle (ORCL) Company Profile & Description - Stock Analysis · stockanalysis.com
- Oracle June 2026 CPU Patches: 270+ Vulnerability Fixes · manageditblog.com
- Prepare Now: Apply the Upcoming Oracle Database Release Update ... · blogs.oracle.com
- Oracle - Investor Relations · investor.oracle.com