Fusion Middleware
Vendor:
First CVE: Apr 13, 2010 · Active for 16 years
313
Total CVEs
More Total CVEs than 100% of tracked products
22.4
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
4.8
Avg CVSS
Higher Avg CVSS than 7% of tracked products
1.0%
KEV Rate
Higher KEV Rate than 96% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Fusion Middleware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 13, 2010
16 years ago
Most Recent CVE
Apr 21, 2026
94 days ago
CVE Severity & Scoring
Fusion Middleware313 CVEs
21%
67%
11%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (0.3%)
Network20 (6.4%)
Unknown291 (93.0%)
Physical0 (0.0%)
Adjacent Network1 (0.3%)
Attack Complexity
Low17 (5.4%)
High5 (1.6%)
Unknown291 (93.0%)
User Interaction
None15 (4.8%)
Unknown291 (93.0%)
Required7 (2.2%)
Privileges Required
Low8 (2.6%)
High1 (0.3%)
None13 (4.2%)
Unknown291 (93.0%)
Top CVEs
Signals from CVEs in this product scope (313 CVEs).
313 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-3152CRITICAL Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality a | Oct 16, 2012 | 9.1 | 98 | YES | YES |
CVE-2012-3153MEDIUM Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality a | Oct 16, 2012 | 6.4 | 91 | NO | YES |
CVE-2012-1710CRITICAL Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and | May 3, 2012 | 9.8 | 74 | YES | NO |
CVE-2013-3763MEDIUM Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to affect confidentiality and integr | Jul 17, 2013 | 5.5 | 64 | NO | YES |
CVE-2010-1622MEDIUM SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request contai | Jun 21, 2010 | 6.0 | 61 | NO | YES |
CVE-2013-1559MEDIUM Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated users to affect availability v | Apr 17, 2013 | 4.0 | 59 | NO | YES |
CVE-2012-0518MEDIUM Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown v | Oct 16, 2012 | 4.7 | 56 | YES | NO |
CVE-2014-2424MEDIUM Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote authenticated users to affect integrity via vectors related | Apr 16, 2014 | 4.0 | 53 | NO | YES |
CVE-2014-4210MEDIUM Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect confidentiality via vectors re | Jul 17, 2014 | 5.0 | 49 | NO | YES |
CVE-2010-3591HIGH Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect confidentiality, integrity, a | Jan 19, 2011 | 9.3 | 47 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (313 CVEs).
CISA KEV
3 CVEs
1.0% of CVEs· 96th percentile
Metasploit
5 CVEs
1.6% of CVEs· 96th percentile
Nuclei
3 CVEs
1.0% of CVEs· 96th percentile
ExploitDB
27 CVEs
8.6% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (313 CVEs).
Media Mentions
Signals from CVEs in this product scope (313 CVEs).
Top CNAs Publishing CVEs For Fusion Middleware
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 9.2.4 | 9 | 4.5 | 2.2% | 0 | 1 |
| 9.2.3 | 2 | 8.4 | 2.3% | 0 | 0 |
| 9.1.0.4 | 1 | 4.0 | 1.1% | 0 | 0 |
| 9.1 | 3 | 6.7 | 3.6% | 0 | 1 |
| 9.0 | 4 | 6.9 | 5.9% | 0 | 1 |
| 8.5.2 | 6 | 1.6 | 0.5% | 0 | 2 |
| 8.5.1 | 8 | 1.6 | 0.6% | 0 | 4 |
| 8.5.0 | 8 | 1.6 | 0.6% | 0 | 4 |
| 8.4.1 | 6 | 4.2 | 1.4% | 0 | 3 |
| 8.4 | 8 | 4.8 | 2.2% | 0 | 1 |
| 8.3.7.0 | 26 | 3.8 | 1.4% | 0 | 3 |
| 8.3.7 | 2 | 2.0 | 0.4% | 0 | 0 |
| 8.3.5.0 | 22 | 3.8 | 2.5% | 0 | 3 |
| 8.3.5 | 2 | 2.0 | 0.4% | 0 | 0 |
| 8.3.2.0 | 5 | 4.4 | 7.3% | 0 | 0 |
| 8.3.0 | 1 | 1.9 | 0.3% | 0 | 0 |
| 8.1.6 | 1 | 4.3 | 1.3% | 0 | 0 |
| 8.1 | 1 | 7.5 | 12.8% | 0 | 0 |
| 8.0 | 5 | 3.9 | 1.1% | 0 | 0 |
| 7.6.2 | 9 | 4.4 | 8.2% | 0 | 6 |