Fusion Middleware

Vendor:

First CVE: Apr 13, 2010 · Active for 16 years

313
Total CVEs
More Total CVEs than 100% of tracked products
22.4
Avg CVEs / Year
Higher CVE frequency than 99% of tracked products
4.8
Avg CVSS
Higher Avg CVSS than 7% of tracked products
1.0%
KEV Rate
Higher KEV Rate than 96% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Fusion Middleware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 13, 2010
16 years ago
Most Recent CVE
Apr 21, 2026
94 days ago

CVE Severity & Scoring

Fusion Middleware313 CVEs
All CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local1 (0.3%)
Network20 (6.4%)
Unknown291 (93.0%)
Physical0 (0.0%)
Adjacent Network1 (0.3%)
Attack Complexity
Low17 (5.4%)
High5 (1.6%)
Unknown291 (93.0%)
User Interaction
None15 (4.8%)
Unknown291 (93.0%)
Required7 (2.2%)
Privileges Required
Low8 (2.6%)
High1 (0.3%)
None13 (4.2%)
Unknown291 (93.0%)

Top CVEs

Signals from CVEs in this product scope (313 CVEs).

313 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality a
Oct 16, 20129.198YESYES
Unspecified vulnerability in the Oracle Reports Developer component in Oracle Fusion Middleware 11.1.1.4, 11.1.1.6, and 11.1.2.0 allows remote attackers to affect confidentiality a
Oct 16, 20126.491NOYES
Unspecified vulnerability in the Oracle WebCenter Forms Recognition component in Oracle Fusion Middleware 10.1.3.5 allows remote attackers to affect confidentiality, integrity, and
May 3, 20129.874YESNO
Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to affect confidentiality and integr
Jul 17, 20135.564NOYES
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request contai
Jun 21, 20106.061NOYES
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote authenticated users to affect availability v
Apr 17, 20134.059NOYES
Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown v
Oct 16, 20124.756YESNO
Unspecified vulnerability in the Oracle Event Processing component in Oracle Fusion Middleware 11.1.1.7.0 allows remote authenticated users to affect integrity via vectors related
Apr 16, 20144.053NOYES
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect confidentiality via vectors re
Jul 17, 20145.049NOYES
Unspecified vulnerability in the Oracle Document Capture component in Oracle Fusion Middleware 10.1.3.4 and 10.1.3.5 allows remote attackers to affect confidentiality, integrity, a
Jan 19, 20119.347NOYES

Exploit Exposure

Signals from CVEs in this product scope (313 CVEs).

CISA KEV
3 CVEs
1.0% of CVEs· 96th percentile
Metasploit
5 CVEs
1.6% of CVEs· 96th percentile
Nuclei
3 CVEs
1.0% of CVEs· 96th percentile
ExploitDB
27 CVEs
8.6% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (313 CVEs).

Media Mentions

Signals from CVEs in this product scope (313 CVEs).

Top CNAs Publishing CVEs For Fusion Middleware

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.2.494.52.2%01
9.2.328.42.3%00
9.1.0.414.01.1%00
9.136.73.6%01
9.046.95.9%01
8.5.261.60.5%02
8.5.181.60.6%04
8.5.081.60.6%04
8.4.164.21.4%03
8.484.82.2%01
8.3.7.0263.81.4%03
8.3.722.00.4%00
8.3.5.0223.82.5%03
8.3.522.00.4%00
8.3.2.054.47.3%00
8.3.011.90.3%00
8.1.614.31.3%00
8.117.512.8%00
8.053.91.1%00
7.6.294.48.2%06