Date: 2026-04-24
Niveau de risque maximal: Critique
Exploitation à distance: Oui
Exploitation locale: Oui
Exécution de code: Oui
La compagnie Oracle a publié des bulletins de sécurité qui concernent de multiples vulnérabilités affectant plusieurs de ses produits. L’exploitation de ces failles pourrait permettre à un attaquant de provoquer un déni de service, un contournement de la politique de sécurité, une exécution de code arbitraire, une atteinte à la confidentialité et l'intégrité des données et compromettre un produit vulnérable.
Produits vulnérables:
- JD Edwards EnterpriseOne Tools, versions 9.2.0.0-9.2.26.1
- Management Cloud Engine, version 25.2.0.0.0
- MySQL Cluster, versions 8.0.0-8.0.44, 8.4.0-8.4.7, 9.0.0-9.5.0
- MySQL Connectors, versions 9.0.0-9.6.0
- MySQL Enterprise Backup, versions 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0
- MySQL Server, versions 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0
- MySQL Shell, versions 8.0.0-8.0.45, 8.4.0-8.4.8, 9.0.0-9.6.0
- MySQL Workbench, versions 8.0.0-8.0.46
- Oracle Access Manager, version 14.1.2.0.0
- Oracle Adapter for Eclipse RDF4J, versions 3.12.0, 21.1.8, 24.1.0
- Oracle Agile Product Lifecycle Management for Process, version 6.2.4
- Oracle Application Development Framework (ADF), versions 12.2.1.4.0, 14.1.2.0.0
- Oracle Application Express, versions 23.2.20, 23.2.21, 24.1.15, 24.1.16, 24.2.13, 24.2.15
- Oracle Application Testing Suite, version 13.3.0.1
- Oracle Autonomous Health Framework, versions 25.11-26.1
- Oracle AutoVue, version 21.1.0
- Oracle Banking Branch, versions 14.5.0.0.0-14.8.0.0.0
- Oracle Banking Cash Management, version 14.8.2.0.0
- Oracle Banking Collections and Recovery, versions 14.6.0.0.0-14.8.0.0.0
- Oracle Banking Corporate Lending, versions 14.5.0.0.0-14.8.0.0.0
- Oracle Banking Corporate Lending Process Management, versions 14.5.0.0.0-14.8.0.0.0
- Oracle Banking Credit Facilities Process Management, versions 14.5.0.0.0-14.8.0.0.0
- Oracle Banking Liquidity Management, versions 14.8.0.0.0, 14.8.1.0.0
- Oracle Banking Origination, versions 14.5.0.0.0-14.8.0.0.0
- Oracle Banking Payments, versions 14.5.0.0.0-14.8.0.0.0
- Oracle Banking Supply Chain Finance, versions 14.5.0.0.0-14.8.0.0.0
- Oracle Banking Trade Finance, versions 14.5.0.0.0-14.8.0.0.0
- Oracle Banking Trade Finance Process Management, versions 14.5.0.0.0-14.8.0.0.0
- Oracle Banking Virtual Account Management, versions 14.5.0.0.0-14.8.0.0.0
- Oracle BI Publisher, versions 7.6.0.0.0, 8.2.0.0.0
- Oracle Blockchain Platform, version 24.1.3
- Oracle Business Activity Monitoring, version 12.2.1.4.0
- Oracle Business Intelligence Enterprise Edition, versions 7.6.0.0.0, 8.2.0.0.0
- Oracle Business Process Management Suite, versions 12.2.1.4.0, 14.1.2.0.0
- Oracle Commerce Guided Search, version 11.4.0
- Oracle Communications Billing and Revenue Management, versions 15.0.0.0.0-15.0.1.0.0, 15.1.0.0.0-15.2.0.0.0
- Oracle Communications BRM - Elastic Charging Engine, versions 15.0.0.0-15.0.1.0, 15.1.0.0-15.2.0.0
- Oracle Communications Cloud Native Core Binding Support Function, version 25.1.200
- Oracle Communications Cloud Native Core Certificate Management, version 25.1.201
- Oracle Communications Cloud Native Core Console, version 25.1.201
- Oracle Communications Cloud Native Core DBTier, versions 25.1.200, 25.2.100
- Oracle Communications Cloud Native Core Network Exposure Function, versions 24.2.1, 24.2.4
- Oracle Communications Cloud Native Core Network Function Cloud Native Environment, versions 25.1.200, 25.2.200
- Oracle Communications Cloud Native Core Network Repository Function, version 25.1.204
- Oracle Communications Cloud Native Core Network Slice Selection Function, versions 25.1.100, 25.1.200
- Oracle Communications Cloud Native Core Policy, versions 25.1.200, 25.1.201, 25.1.202
- Oracle Communications Cloud Native Core Security Edge Protection Proxy, versions 25.1.200, 25.1.201, 25.2.100
- Oracle Communications Cloud Native Core Service Communication Proxy, versions 25.1.100, 25.1.200, 25.1.202, 25.2.100
- Oracle Communications Cloud Native Core Unified Data Repository, versions 25.1.100, 25.1.200
- Oracle Communications Convergence, version 3.0.3.4.0
- Oracle Communications EAGLE, version 47.0
- Oracle Communications EAGLE Application Processor, versions 17.0-17.1
- Oracle Communications EAGLE Element Management System, version 47.0.0.1.0
- Oracle Communications EAGLE LNP Application Processor, version 11.0
- Oracle Communications Element Manager, versions 9.0.0-9.0.4
- Oracle Communications Instant Messaging Server, version 10.0.1.8.0
- Oracle Communications LSMS, version 14.0
- Oracle Communications Messaging Server, version 8.1.0.0.0
- Oracle Communications Network Integrity, versions 7.3.6, 7.4.0, 7.5.0, 8.0.0
- Oracle Communications Offline Mediation Controller, versions 15.0.0.0.0-15.0.1.0.0, 15.1.0.0.0-15.2.0.0.0
- Oracle Communications Operations Monitor, versions 5.2, 6.0, 6.1
- Oracle Communications Order and Service Management, versions 7.5.0, 8.0.0
- Oracle Communications Performance Intelligence Center, versions 10.5.0.0-10.5.0.2
- Oracle Communications Policy Management, versions 15.0.0.0.0, 15.0.0.1.0
- Oracle Communications Service Catalog and Design, versions 8.0.0.6.0, 8.1.0.5.0, 8.2.0.2.0
- Oracle Communications Session Border Controller, versions 9.3.0, 10.0.0, 10.1.0
- Oracle Communications Session Report Manager, versions 9.0.0-9.0.4
- Oracle Communications Unified Assurance, versions 6.1.1-7.0.0
- Oracle Communications Unified Inventory Management, versions 7.5.0-7.5.1, 7.6.0-7.8.0, 8.0.0
- Oracle Configuration Manager, versions 13.5, 24.1
- Oracle Data Integrator, versions 12.2.1.4.0, 14.1.2.0.0
- Oracle Database Server, versions 12.1.0.2.0, 12.2.0.1.0, 19.3-19.30, 21.3-21.21, 23.4.0-23.26.1
- Oracle Documaker, versions 12.7.2-13.0.2
- Oracle E-Business Suite, versions 12.2.3-12.2.15, 15.0
- Oracle Enterprise Communications Broker, versions 4.2.0, 5.0.0
- Oracle Enterprise Manager Base Platform, versions 13.5, 24.1
- Oracle Enterprise Manager for Fusion Middleware, versions 13.5, 24.1
- Oracle Enterprise Operations Monitor, version 6.1.0.0.0
- Oracle Essbase, version 21.8.1.0.0
- Oracle Financial Services Analytical Applications Infrastructure, versions 8.0.7.9, 8.0.8.7, 8.1.2.5
- Oracle Financial Services Behavior Detection Platform, versions 8.0.8.1, 8.1.2.10, 8.1.2.11
- Oracle Financial Services Compliance Studio, version 8.1.2.9
- Oracle Financial Services Customer Screening, version 8.1.2.8.0
- Oracle Financial Services Enterprise Case Management, versions 8.0.8.2, 8.1.2.10, 8.1.2.11
- Oracle Financial Services Lending and Leasing, versions 14.8.0.0.0, 14.10.0.0.0-14.12.0.0.0
- Oracle Financial Services Model Management and Governance, version 8.1.2.7
- Oracle Financial Services Regulatory Reporting, versions 8.1.2.10, 8.1.2.11
- Oracle Financial Services Trade-Based Anti Money Laundering Enterprise Edition, version 8.0.8
- Oracle Financial Services Transaction Filtering, version 8.1.2.8.0
- Oracle FLEXCUBE Enterprise Limits and Collateral Management, versions 14.5.0.0.0-14.8.0.0.0
- Oracle Fusion Middleware, versions 12.2.1.4.0, 14.1.2.0.0
- Oracle Global Lifecycle Management OPatchAuto, versions 12.2.0.1.16-12.2.0.1.49
- Oracle GoldenGate, versions 23.4-23.26.1
- Oracle GoldenGate Big Data and Application Adapters, versions 19.1.0.0.0-19.1.0.0.21, 21.3-21.21, 23.4-23.10
- Oracle GoldenGate Stream Analytics, versions 19.1.0.0.0-19.1.0.0.14
- Oracle GraalVM Enterprise Edition, version 21.3.17
- Oracle GraalVM for JDK, versions 17.0.18, 21.0.10
- Oracle Graph Server and Client, versions 24.4.5, 25.4.1, 26.1.0
- Oracle Hospitality Cruise Shipboard Property Management (SPMS), versions 23.1.5-23.3.0
- Oracle HTTP Server, versions 12.2.1.4.0, 14.1.2.0.0
- Oracle Hyperion Infrastructure Technology, version 11.2.24.0.0
- Oracle Identity Manager, versions 12.2.1.4.0, 14.1.2.0.0, 14.1.2.1.0
- Oracle Identity Manager Connector, version 12.2.1.4.0
- Oracle Insurance Policy Administration J2EE, versions 11.3.1.0, 11.3.2.0, 12.0.5.0, 12.1.1.0
- Oracle Insurance Policy Administration Operational Data Store for Life and Annuity, version 1.0.2.1
- Oracle Java SE, versions 8u481, 8u481-b50, 8u481-perf, 11.0.30, 17.0.18, 21.0.10, 25.0.1, 25.0.2, 26
- Oracle Life Sciences Empirica Signal, versions 9.2.1-9.2.3
- Oracle Life Sciences InForm, versions 7.0.1.0, 7.0.1.1
- Oracle Managed File Transfer, versions 12.2.1.4.0, 14.1.2.0.0
- Oracle Middleware Common Libraries and Tools, versions 12.2.1.4.0, 14.1.2.0.0
- Oracle NoSQL Database, versions 1.6.5, 1.7.0
- Oracle Outside In Technology, version 8.5.8
- Oracle REST Data Services, versions 24.2.0, 24.2.1, 24.3.0, 24.3.1, 24.4.0, 25.1.1, 25.2.0, 25.2.1, 25.2.2, 25.2.3, 25.3.0, 25.3.1, 25.4.0
- Oracle Retail Fiscal Management, version 14.2
- Oracle Retail Integration Bus, versions 16.0.3, 19.0.1
- Oracle Retail Merchandise Financial Planning, versions 15.0, 16.0
- Oracle Retail Predictive Application Server, version 16.0.3
- Oracle Retail Price Management, version 16.0.3
- Oracle Retail Service Backbone, versions 16.0.3, 19.0.1
- Oracle Retail Xstore Point of Service, versions 21.0.5, 22.0.3
- Oracle Security Service, versions 12.1.3.0.0, 12.2.1.4.0
- Oracle SOA Suite, versions 12.2.1.4.0, 14.1.2.0.0
- Oracle TimesTen In-Memory Database, versions 18.1.4, 22.1.1
- Oracle Tuxedo, versions 22.1.0, 22.1.1
- Oracle Utilities Live Energy Connect, versions 7.1.0.0.45, 25.12.0.0.0
- Oracle Utilities Network Management System, versions 2.4.0.1.31, 2.5.0.1.16, 2.5.0.2.10, 2.6.0.1.10, 2.6.0.2.5, 2.6.0.2.6
- Oracle VM VirtualBox, version 7.2.6
- Oracle Web Services Manager, versions 12.2.1.4.0, 14.1.2.0.0
- Oracle WebCenter Forms Recognition, version 14.1.1.0.0
- Oracle WebCenter Sites, versions 12.2.1.4.0, 14.1.2.0.0
- Oracle WebLogic Server, versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0, 15.1.1.0.0
- PeopleSoft Enterprise CC Common Application Objects, version 9.2
- PeopleSoft Enterprise FIN Contracts, version 9.2
- PeopleSoft Enterprise FIN Maintenance Management, version 9.2
- PeopleSoft Enterprise FIN Project Costing, version 9.2
- PeopleSoft Enterprise HCM Absence Management, version 9.2
- Primavera P6 Enterprise Project Portfolio Management, versions 21.12.0.0-21.12.21.6, 22.12.0.0-22.12.21.1, 23.12.0.0-23.12.18.0, 24.12.0.0-24.12.13.0, 25.12.0.0-25.12.2.0
- Siebel Applications, versions 17.0-26.2
- Sun ZFS Storage Appliance Kit, version 8.8
CVE: CVE-2021-0341, CVE-2021-22573, CVE-2021-45046, CVE-2022-45047, CVE-2022-45688, CVE-2023-1436, CVE-2023-2976, CVE-2023-26464, CVE-2023-34034, CVE-2023-34453, CVE-2023-44981, CVE-2023-52428, CVE-2024-5535, CVE-2024-6387, CVE-2024-8184, CVE-2024-13009, CVE-2024-29371, CVE-2024-29857, CVE-2024-43394, CVE-2024-51504, CVE-2024-56406, CVE-2025-0725, CVE-2025-1948, CVE-2025-5115, CVE-2025-5318, CVE-2025-6965, CVE-2025-7962, CVE-2025-8194, CVE-2025-8869, CVE-2025-9086, CVE-2025-9230, CVE-2025-9900, CVE-2025-12383, CVE-2025-12543, CVE-2025-13151, CVE-2025-13601, CVE-2025-15467, CVE-2025-24970, CVE-2025-26333, CVE-2025-27817, CVE-2025-27820, CVE-2025-27821, CVE-2025-32990, CVE-2025-33042, CVE-2025-35036, CVE-2025-41248, CVE-2025-41249, CVE-2025-41253, CVE-2025-43967, CVE-2025-46762, CVE-2025-48734, CVE-2025-48913, CVE-2025-48976, CVE-2025-52999, CVE-2025-53643, CVE-2025-55130, CVE-2025-55163, CVE-2025-55754, CVE-2025-58050, CVE-2025-58057, CVE-2025-58098, CVE-2025-58754, CVE-2025-59465, CVE-2025-59775, CVE-2025-61729, CVE-2025-64775, CVE-2025-65018, CVE-2025-66418, CVE-2025-66566, CVE-2025-67635, CVE-2025-68121, CVE-2025-68431, CVE-2025-68615, CVE-2025-68973, CVE-2025-69223, CVE-2026-0861, CVE-2026-20652, CVE-2026-21441, CVE-2026-21452, CVE-2026-21939, CVE-2026-21945, CVE-2026-21997, CVE-2026-22010, CVE-2026-22011, CVE-2026-22016, CVE-2026-22022, CVE-2026-22184, CVE-2026-22801, CVE-2026-23490, CVE-2026-24734, CVE-2026-25210, CVE-2026-25646, CVE-2026-25968, CVE-2026-25990, CVE-2026-27099, CVE-2026-27727, CVE-2026-27830, CVE-2026-31790, CVE-2026-33870, CVE-2026-34275, CVE-2026-34279, CVE-2026-34282, CVE-2026-34285, CVE-2026-34286, CVE-2026-34287, CVE-2026-34290, CVE-2026-34291, CVE-2026-34292, CVE-2026-34297, CVE-2026-34305, CVE-2026-34309, CVE-2026-34310, CVE-2026-34320, CVE-2026-35229, CVE-2026-35230, CVE-2026-35231, CVE-2026-35242, CVE-2026-35243, CVE-2026-35245, CVE-2026-35246, CVE-2026-35251