Goldengate
Vendor:
First CVE: Jan 21, 2016 · Active for 10 years
24
Total CVEs
More Total CVEs than 96% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 66% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Goldengate over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2016
10 years ago
Most Recent CVE
Jul 21, 2026
7 days ago
CVE Severity & Scoring
Goldengate24 CVEs
33%
54%
13%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local1 (4.2%)
Network19 (79.2%)
Unknown3 (12.5%)
Physical0 (0.0%)
Adjacent Network1 (4.2%)
Attack Complexity
Low16 (66.7%)
High5 (20.8%)
Unknown3 (12.5%)
User Interaction
None14 (58.3%)
Unknown3 (12.5%)
Required7 (29.2%)
Privileges Required
Low3 (12.5%)
High1 (4.2%)
None17 (70.8%)
Unknown3 (12.5%)
Top CVEs
Signals from CVEs in this product scope (24 CVEs).
24 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5645CRITICAL In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payloa | Apr 17, 2017 | 9.8 | 86 | NO | YES |
CVE-2021-4104HIGH JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName | Dec 14, 2021 | 7.5 | 70 | NO | NO |
CVE-2021-23017HIGH A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in | Jun 1, 2021 | 7.7 | 65 | NO | YES |
CVE-2026-60157HIGH Vulnerability in Oracle GoldenGate (component: Service Manager). Supported versions that are affected are 19.1.0.0.0-19.29.0.0, 21.3-21.21 and 23.4-23.26.1.0.0. Easily exploitabl | Jul 21, 2026 | 8.8 | 33 | NO | NO |
CVE-2018-2913CRITICAL Vulnerability in the Oracle GoldenGate component of Oracle GoldenGate (subcomponent: Monitoring Manager). Supported versions that are affected are 12.1.2.1.0, 12.2.0.2.0 and 12.3.0 | Oct 17, 2018 | 10.0 | 33 | NO | NO |
CVE-2016-0452HIGH Unspecified vulnerability in the Oracle GoldenGate component in Oracle GoldenGate 11.2 and 12.1.2 allows remote attackers to affect confidentiality, integrity, and availability via | Jan 21, 2016 | 10.0 | 32 | NO | NO |
CVE-2026-61106HIGH Vulnerability in Oracle GoldenGate (component: Config Service Executable). Supported versions that are affected are 23.4-23.26.2. Difficult to exploit vulnerability allows unauthe | Jul 21, 2026 | 8.1 | 31 | NO | NO |
CVE-2021-3749HIGH axios is vulnerable to Inefficient Regular Expression Complexity | Aug 31, 2021 | 7.5 | 31 | NO | NO |
CVE-2018-1311HIGH The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained ver | Dec 18, 2019 | 8.1 | 31 | NO | NO |
CVE-2016-0451HIGH Unspecified vulnerability in the Oracle GoldenGate component in Oracle GoldenGate 11.2 and 12.1.2 allows remote attackers to affect confidentiality, integrity, and availability via | Jan 21, 2016 | 10.0 | 31 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (24 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.2% of CVEs· 97th percentile
ExploitDB
1 CVE
4.2% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (24 CVEs).
Media Mentions
Signals from CVEs in this product scope (24 CVEs).
Top CNAs Publishing CVEs For Goldengate
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 19.1.0.0.0.210420 | 1 | 6.5 | 1.7% | 0 | 0 |
| 12.3.2.1.1 | 1 | 9.8 | 89.0% | 0 | 1 |
| 12.3.0.1.2 | 1 | 6.1 | 2.1% | 0 | 0 |
| 12.3.0.1.0 | 3 | 8.3 | 4.0% | 0 | 0 |
| 12.2.0.2.0 | 3 | 8.3 | 4.0% | 0 | 0 |
| 12.2.0.1 | 1 | 8.6 | 1.9% | 0 | 0 |
| 12.1.2.1.0 | 3 | 8.3 | 4.0% | 0 | 0 |
| 12.1.2 | 3 | 8.3 | 5.5% | 0 | 0 |
| 11.2 | 3 | 8.3 | 5.5% | 0 | 0 |