Goldengate

Vendor:

First CVE: Jan 21, 2016 · Active for 10 years

24
Total CVEs
More Total CVEs than 96% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
7.8
Avg CVSS
Higher Avg CVSS than 66% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Goldengate over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2016
10 years ago
Most Recent CVE
Jul 21, 2026
7 days ago

CVE Severity & Scoring

Goldengate24 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local1 (4.2%)
Network19 (79.2%)
Unknown3 (12.5%)
Physical0 (0.0%)
Adjacent Network1 (4.2%)
Attack Complexity
Low16 (66.7%)
High5 (20.8%)
Unknown3 (12.5%)
User Interaction
None14 (58.3%)
Unknown3 (12.5%)
Required7 (29.2%)
Privileges Required
Low3 (12.5%)
High1 (4.2%)
None17 (70.8%)
Unknown3 (12.5%)

Top CVEs

Signals from CVEs in this product scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payloa
Apr 17, 20179.886NOYES
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName
Dec 14, 20217.570NONO
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from the DNS server to cause 1-byte memory overwrite, resulting in
Jun 1, 20217.765NOYES
Vulnerability in Oracle GoldenGate (component: Service Manager). Supported versions that are affected are 19.1.0.0.0-19.29.0.0, 21.3-21.21 and 23.4-23.26.1.0.0. Easily exploitabl
Jul 21, 20268.833NONO
Vulnerability in the Oracle GoldenGate component of Oracle GoldenGate (subcomponent: Monitoring Manager). Supported versions that are affected are 12.1.2.1.0, 12.2.0.2.0 and 12.3.0
Oct 17, 201810.033NONO
Unspecified vulnerability in the Oracle GoldenGate component in Oracle GoldenGate 11.2 and 12.1.2 allows remote attackers to affect confidentiality, integrity, and availability via
Jan 21, 201610.032NONO
Vulnerability in Oracle GoldenGate (component: Config Service Executable). Supported versions that are affected are 23.4-23.26.2. Difficult to exploit vulnerability allows unauthe
Jul 21, 20268.131NONO
axios is vulnerable to Inefficient Regular Expression Complexity
Aug 31, 20217.531NONO
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained ver
Dec 18, 20198.131NONO
Unspecified vulnerability in the Oracle GoldenGate component in Oracle GoldenGate 11.2 and 12.1.2 allows remote attackers to affect confidentiality, integrity, and availability via
Jan 21, 201610.031NONO

Exploit Exposure

Signals from CVEs in this product scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
4.2% of CVEs· 97th percentile
ExploitDB
1 CVE
4.2% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (24 CVEs).

Media Mentions

Signals from CVEs in this product scope (24 CVEs).

Top CNAs Publishing CVEs For Goldengate

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
19.1.0.0.0.21042016.51.7%00
12.3.2.1.119.889.0%01
12.3.0.1.216.12.1%00
12.3.0.1.038.34.0%00
12.2.0.2.038.34.0%00
12.2.0.118.61.9%00
12.1.2.1.038.34.0%00
12.1.238.35.5%00
11.238.35.5%00