Ilearning
Vendor:
First CVE: Jul 17, 2013 · Active for 13 years
16
Total CVEs
More Total CVEs than 92% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.9
Avg CVSS
Higher Avg CVSS than 20% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ilearning over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2013
13 years ago
Most Recent CVE
Jan 24, 2022
1,642 days ago
CVE Severity & Scoring
Ilearning16 CVEs
69%
31%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (6.3%)
Network7 (43.8%)
Unknown8 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (43.8%)
High1 (6.3%)
Unknown8 (50.0%)
User Interaction
None2 (12.5%)
Unknown8 (50.0%)
Required6 (37.5%)
Privileges Required
Low1 (6.3%)
High0 (0.0%)
None7 (43.8%)
Unknown8 (50.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-2351HIGH Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulne | Jul 21, 2021 | 8.3 | 28 | NO | NO |
CVE-2018-2989HIGH Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Administration). The supported version that is affected is 6.2. Easily exploitable vulner | Jul 18, 2018 | 8.2 | 26 | NO | NO |
CVE-2018-3146HIGH Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Administration). Supported versions that are affected are 6.1 and 6.2. Easily exploitable | Oct 17, 2018 | 8.2 | 25 | NO | NO |
CVE-2022-23437MEDIUM There's a vulnerability within the Apache Xerces Java (XercesJ) XML parser when handling specially crafted XML document payloads. This causes, the XercesJ XML parser to wait in an | Jan 24, 2022 | 6.5 | 24 | NO | NO |
CVE-2017-10199HIGH Vulnerability in the Oracle iLearning component of Oracle iLearning (subcomponent: Learner Pages). The supported version that is affected is 6.2. Easily exploitable vulnerability a | Aug 8, 2017 | 8.2 | 23 | NO | NO |
CVE-2020-14595HIGH Vulnerability in the Oracle iLearning product of Oracle iLearning (component: Assessment Manager). Supported versions that are affected are 6.1 and 6.1.1. Easily exploitable vulner | Jul 15, 2020 | 8.2 | 21 | NO | NO |
CVE-2013-5822MEDIUM Unspecified vulnerability in the Oracle iLearning component in Oracle iLearning 5.2.1 and 6.0 allows remote attackers to affect confidentiality, integrity, and availability via unk | Oct 16, 2013 | 6.8 | 21 | NO | NO |
CVE-2020-17521MEDIUM Apache Groovy provides extension methods to aid with creating temporary directories. Prior to this fix, Groovy's implementation of those extension methods was using a now supersede | Dec 7, 2020 | 5.5 | 20 | NO | NO |
CVE-2014-0389MEDIUM Unspecified vulnerability in Oracle iLearning 6.0 allows remote attackers to affect integrity via unknown vectors related to Learner Pages. | Jan 15, 2014 | 4.3 | 18 | NO | NO |
CVE-2020-2709MEDIUM Vulnerability in the Oracle iLearning product of Oracle iLearning (component: Learner Pages). The supported version that is affected is 6.1. Easily exploitable vulnerability allows | Jan 15, 2020 | 4.7 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Ilearning
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.3 | 3 | 6.8 | 2.7% | 0 | 0 |
| 6.2 | 6 | 7.5 | 2.2% | 0 | 0 |
| 6.1.1 | 1 | 8.2 | 2.1% | 0 | 0 |
| 6.1 | 7 | 5.5 | 1.4% | 0 | 0 |
| 6.0 | 8 | 4.6 | 1.4% | 0 | 0 |
| 5.2.1 | 3 | 5.1 | 1.2% | 0 | 0 |