CISA KEV · catalog date Mar 25, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2017-12617
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g.
Exploited in the wild (CISA KEV since Mar 25, 2022). NVD reports CVSS 3.1 8.1. EPSS estimates 100.0% exploit likelihood as of Aug 2, 2026.
As of Aug 27, 2026
Normalized restatement
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
- State
- PUBLISHED
- Published
- Oct 3, 2017
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCAapacheOriginal evidence ↗
Record text: When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Inspect raw assertion
- Field
container- Value
- When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Apache Tomcat Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Apache Tomcat Remote Code Execution Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 99.99% probability · 99.98th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999880000000; percentile 0.999840000000
FIRST EPSS · score date Aug 2, 2026 · 100th percentile · first observed Aug 2, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
Inspect raw assertion
- Field
container- Value
- When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Apache Tomcat Remote Code Execution Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Apache Tomcat Remote Code Execution Vulnerability
99.99% probability · 99.98th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.999880000000; percentile 0.999840000000
Applicability
Cited product scope
Grouped from 6 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
59 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "9.0.0.M1 to 9.0.0"}, {"status": "affected", "version": "8.5.0 to 8.5.22"}, {"status": "affected", "version": "8.0.0.RC1 to 8.0.46"}, {"status": "affected", "version": "7.0.0 to 7.0.81"}]product-b4642eb973ddbe1a3e24c089bf036c528ab40d12c3eab0fae6fd551615375441Linked exactInspect raw assertions
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 8.0; through excluding 8.0.47
- Match ID
2c385fe9-f78c-49bc-ae87-5fe1a9bd7ed3
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 7.0.0; through excluding 7.0.82
- Match ID
a7286e06-da84-401d-8fb8-deef6a171c88
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- from including 9.0.0; through excluding 9.0.1
- Match ID
817d7e47-947e-4a2f-a8ab-1302d5df6684
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 8.5.0; through excluding 8.5.23
- Match ID
ef72650e-5826-4abb-9b7d-43c96db3b9b7
product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2Linked exactInspect raw assertions
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:esm:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b3293e55-5506-4587-a318-d1734f781c09
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7a5301bf-1402-4be0-a0f8-69fbe79bc6d6
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8d305f7a-d159-4716-ab26-5e38bb5cd991
cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9070c9d8-a14a-467f-8253-33b966c16886
product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exactInspect raw assertion
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
16f59a04-14cf-49e2-9973-645477ea09da
product-7622e4e001e04d07e68c37d95f4e8879bc2e631632b5d522e6504407a3f05f79Linked exactInspect raw assertions
cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:vmware_vsphere:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 9.5
- Match ID
0cb28af5-5af0-4475-a7b6-12e1795ffdcb
cpe:2.3:a:netapp:active_iq_unified_manager:*:*:*:*:*:windows:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 7.3
- Match ID
bd075607-09b7-493e-8611-66d041ffda62
product-a3ee6e9aad325f4582e56f47f80e10ac773b295ac08b0f810dbc94297c412a26Linked exactInspect raw assertion
cpe:2.3:o:netapp:element:-:*:*:*:*:vcenter_server:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5e1de4f5-9094-4c73-aa1b-5c902f38dd24
product-1e7e71c5224a6f4135c855890a7cd875f6ac32bf0024c6ee2e888da0212d267eLinked exactInspect raw assertion
cpe:2.3:a:netapp:oncommand_balance:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7dcbcc5d-c396-47a8-adf4-d3a2c4377fb1
product-6bac5e5dc0babe5d628e246786e711716ddfb068132218ad0dd5123beb466ec4Linked exactInspect raw assertion
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f1be6c1f-2565-4e97-92aa-16563e5660a5
product-96fd4aeba8f0231e1d0f6ca7ae786e70d484258209c2dd2c10b095c6d07c6180Linked exactInspect raw assertion
cpe:2.3:a:netapp:oncommand_shift:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
3bd81527-a341-42c3-9ab9-880d3db04b08
product-afac260708bb4bb1a51e28ce6b95f0356203366f8c8ffd2c790c3109033fc4fdLinked exactInspect raw assertion
cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5735e553-9731-4aac-bcff-989377f817b3
product-72194eb69952d9519f325006ffebfb4101503889dc70b262bb3ce2ae0ce452a2Linked exactInspect raw assertion
cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bdfb1169-41a0-4a86-8e4f-fda9730b1e94
product-61e478de61e41c69453ce682831f19e397da7c841b4f820e06d8d4a68fa2ec9bLinked exactInspect raw assertions
cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ed43772f-d280-42f6-a292-7198284d6fe7
cpe:2.3:a:oracle:agile_plm:9.3.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ccf62b0c-a8bd-40e6-9e4e-e684f4e87acd
cpe:2.3:a:oracle:agile_plm:9.3.3:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d14abf04-e460-4911-9c6c-b7bcefe68e9d
cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c650fedb-e903-4c2d-ad40-282ab5f2e3c2
product-03e952e5feb49cbab6d67785e54883eca72c93fde4ee0531366703d67c7f92f5Linked exactInspect raw assertion
cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
622b95f1-8fa4-4aa6-9b68-5fe4302ba150
product-9b45fbecab58751fca5da875ab85e9592dc8183d7ca3ef52fcff184df2cbdcffLinked exactInspect raw assertions
cpe:2.3:a:oracle:endeca_information_discovery_integrator:3.2.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7e856b4a-6ae7-4317-921a-35b4d2048652
cpe:2.3:a:oracle:endeca_information_discovery_integrator:3.1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8b65cd29-c729-42ac-925e-014ba19581e2
product-794e37fda632c2a45a36473cbb3be31a77af276763c44128eea6fbafba1fc418Linked exactInspect raw assertion
cpe:2.3:a:oracle:enterprise_manager_for_mysql_database:12.1.0.4.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
815e0c5e-00df-4ad2-ae97-a752b3dc1631
product-ba2f6e9f72c1209c147c5ead6bbf71a825fad4347275bbe719bc9a5db936c36cLinked exactInspect raw assertions
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 9
- Logic
- OR
- Version bounds
- from including 8.0.0.0.0; through including 8.0.9.0.0
- Match ID
9380a86a-7a58-477f-a697-b6692e18b4b9
cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 8
- Logic
- OR
- Version bounds
- from including 7.3.3.0.0; through including 7.3.5.3.0
- Match ID
4c3cfcce-a8d4-4b78-9c37-88238580b5da
product-1cf0ea54fa18ce08ce83460c9225344eb0ba47c166452e5e3b03fdf68df31ba9Linked exactInspect raw assertions
cpe:2.3:a:oracle:fmw_platform:12.2.1.3.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9c5e9a12-bfe9-4963-a360-a34168a6bf6a
cpe:2.3:a:oracle:fmw_platform:12.2.1.2.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
657387a7-dfd9-4cdc-968a-3f3970fde224
product-0c2e4bc5085e04c17e1c18fc8c10b5f73cf112ccd8fce369b4fbe4c9e43d5835Linked exactInspect raw assertion
cpe:2.3:a:oracle:health_sciences_empirica_inspections:1.0.1.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
26cd44c0-f9dd-46f0-a4c1-2c2639217b4d
product-7744ccbcd8b62a3ac1f4418de6eb0aa032258e4ecfa917b191c1e0094cc6ca9bLinked exactInspect raw assertions
cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1a3dc116-2844-47a1-bec2-d0675dd97148
cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e0f1df3e-0f2d-4efc-9a3e-f72149c8ae94
product-5d00280b7e61e03519c1b83650a5d87f654dd625a18111d908ab01d840aacb09Linked exactInspect raw assertions
cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b9c9bc66-fa5f-4774-9bda-7ab88e2839c4
cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 15
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
82ea4ba7-c38b-4af3-8914-9e3d089ebdd4
product-79c39923ad359eddc9f5b7de16c6ab4823d9fc2a83f182fbae06a6968653fbb3Linked exactInspect raw assertion
cpe:2.3:a:oracle:management_pack:11.2.1.0.13:*:*:*:*:goldengate:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5eb9e1ea-e136-4b09-9bbb-d7d48d993349
product-26246d195a9a609d24412574e83b4b4680bf713e7c6220d72f079661be8ca319Linked exactInspect raw assertion
cpe:2.3:a:oracle:micros_lucas:2.9.5:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
98ee20fd-3d21-4e23-95b8-7bd13816eb95
product-97b8db65c678f6a8f36811670c4d788f6a86e3041899c5a507c6cb04922f8b99Linked exactInspect raw assertions
cpe:2.3:a:oracle:micros_retail_xbri_loss_prevention:10.8.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 24
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c1e3c86b-4483-430a-856d-7eab7d388d2e
cpe:2.3:a:oracle:micros_retail_xbri_loss_prevention:10.8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 23
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fa3f5761-e2a0-4f67-bae1-503877676bf3
cpe:2.3:a:oracle:micros_retail_xbri_loss_prevention:10.0.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
78933dd0-f774-4e60-bc66-d5a57919717a
cpe:2.3:a:oracle:micros_retail_xbri_loss_prevention:10.5.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8eca7a7e-8177-4fd4-b9b9-f4b1b6f43f98
cpe:2.3:a:oracle:micros_retail_xbri_loss_prevention:10.7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 22
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
eeb4eb87-5abb-437d-bdac-fb64f33929fa
cpe:2.3:a:oracle:micros_retail_xbri_loss_prevention:10.6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 21
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
73c9a2ad-f384-44d5-ab33-86b7250760a5
product-57d551f18f44e8d3873b139bff1d5a2db2f13c717b3d0295e687bd95ab213facLinked exactInspect raw assertions
cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 25
- Logic
- OR
- Version bounds
- through including 3.3.6.3293
- Match ID
ff9c223c-bc90-4253-a009-53dedee9c1cc
cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 26
- Logic
- OR
- Version bounds
- from including 3.4.0; through including 3.4.4.4226
- Match ID
52886ba2-204e-4f0e-b22f-ce5fdfcc98b5
cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 27
- Logic
- OR
- Version bounds
- from including 4.0.0; through including 4.0.0.5135
- Match ID
6470ab3f-ade2-4ba2-a6b9-e094c927cc77
product-081282dd55ba60346e3501ac0beb7e4bdc31c893cc1cac88d474cb385f594182Linked exactInspect raw assertions
cpe:2.3:a:oracle:retail_advanced_inventory_planning:15.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 31
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
517e0654-f1de-43c4-90b5-fb90ca31734b
cpe:2.3:a:oracle:retail_advanced_inventory_planning:14.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 30
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
56239dbd-e294-44a4-9dd3-ceec58c1bc0c
cpe:2.3:a:oracle:retail_advanced_inventory_planning:13.4:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 29
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fe65a212-7385-4973-a9c8-fb9c2f9f745f
cpe:2.3:a:oracle:retail_advanced_inventory_planning:13.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 28
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d8193a06-3f6b-4f5a-aa58-b1b0ab3a87a3
Affected-product evidence
Accepted scope and product mapping
58 canonical links · 1 source-reported links
vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-03e952e5feb49cbab6d67785e54883eca72c93fde4ee0531366703d67c7f92f5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2cab56e8-1212-4997-b02e-a494ca978a3evendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-081282dd55ba60346e3501ac0beb7e4bdc31c893cc1cac88d474cb385f594182
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0db1f696-c06d-4306-a0e4-31d1e2c6aad90eb2a965-68d1-4bb0-b638-90d3b09fdbba167ac520-d451-4481-9f45-e23d013905203cfe3192-1799-460c-9891-fcafd0c9349avendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-0c2e4bc5085e04c17e1c18fc8c10b5f73cf112ccd8fce369b4fbe4c9e43d5835
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
530fd19d-1a04-48ad-8f74-ce432f10b7efvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-0ec93b384f923447c109f9a0331b22e72852d91f1740883ca2c7fe228c708d1c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7842955a-f5c9-4193-8c88-77170bfc388de50d93db-306e-4b13-ab20-21567c4a5321vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-0f3c5d8c07e690c486e2e297e55bea9245b06546874f1021e18a5b6abda9f72a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8ff4b820-5a15-4e6b-aaad-6a66f13a23bae1a65a19-e0a3-4fe9-a0fb-4ed020d50f39vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-0f45fea3ee91f8d05bc4be8887b754209e8e66961c6f444f57c5e98ab08d2d8e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2a532c5c-a462-422b-b390-cc7a4bfd61a65d337fe5-64c0-47fe-ab9f-5c2e48e2688b6653273f-7efb-4bbc-95a4-415754e34dbdfcc97088-dac4-45dd-9937-a4a0382f4105vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-1036ce7e379a16145bf7c93d6a3caa18af2177eb64285e9b92d66fc0001b62db
- Source class
- Nvd cpe vulnerable target
- Assertions
- 8
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1efde407-c819-45cc-95ef-ccb4da0aa1ee23e503b6-e492-4459-8a67-76f3e01e23f838cc61f3-cad0-4b2a-bb08-92b1267de99754a04788-dd8c-491d-a689-114d343273dc86dc3492-ca70-403d-9205-dba5bc88747491c66769-b2f3-4fa1-82c4-f02b237dc82f99337e0e-4651-4e5e-8996-344706415683bb27d980-ee0e-4058-a1cb-eda0fa5ef0e3vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-15f4f1a5bcca45ff8afd621a4b792cc7852435ed472d651d3a9035155147848a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c4247176-9d57-4617-a217-09f969c25659vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-178c99fc15441567220d6cffb03093506e9eb302df09596871379c3156151980
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f51030f8-77ff-4fc9-a39b-5ca2fb6c5161vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-1cf0ea54fa18ce08ce83460c9225344eb0ba47c166452e5e3b03fdf68df31ba9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
69d82248-61db-43f8-be1f-fe576251f9f5859df2ee-e780-4354-86ff-85a67a4b4772vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-1e7e71c5224a6f4135c855890a7cd875f6ac32bf0024c6ee2e888da0212d267e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
bb90e245-e4fb-4c7c-ae11-f67f1eb17a5bvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-2399ab72875c0412119f3ccdf419e9b3e4099cfc8cd41049539b12d53e7629a8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
61724390-5d28-48d8-a173-39d58c546b70vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-26246d195a9a609d24412574e83b4b4680bf713e7c6220d72f079661be8ca319
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
64ff2f64-0b37-4215-88de-30e2a8be32bevendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-280a720ee74a48a2d9e1641fe847ee843978848900003d7939566317c7359fb5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
189afd6e-25b3-4906-ab9b-89db43fa558d9e1d78df-3fda-4375-aa3e-bdb349020a47a4472b79-dc53-4423-ab65-1c53240d57ccac4c6849-466d-4ee6-9b73-3e793cfea13fvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-323efd260a3034fd5a801fc0892ece9f9134f88683f3fd325c7ee2fdc93956fd
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0a652a9d-2f46-478d-bcea-7292efa947844389ff82-0ca4-4723-9b1b-30f9d55bf0705e70cd17-f3e0-488c-bc1f-174f21caaec160edf125-2df5-4080-ad9f-4070ca01548bvendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
51b581bf-efb2-4ea6-bba2-c239c038a9c1vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-41c5cb18a55dd692691af6f4e4224d4919937f66d2f26def7a1ccb9123341fbb
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8b4fbd87-578b-474f-a787-a00a148ef7d4vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-4b953f9533c4043e30b8b437c15b83696a9a0e3941c7edc2b538f652abe2fd17
- Source class
- Nvd cpe vulnerable target
- Assertions
- 8
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3808bd81-6ab6-4cd5-bd43-69423f5faadb4731c2b6-8b9a-4202-867c-b75d85b9d92e52810774-6f27-4d68-9883-04bf6085f69854eb7e73-74fe-41db-91b4-0296eae5be848e1d712b-2049-40a8-acea-21282eb50a61a2cae4a7-650b-493b-a2ff-c9bfd3be1ccfb04989ac-177e-49b2-b359-a10b58185aaeeab286c7-c315-43aa-b3af-6e641a6d0a0cvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-51b2c4edc8b5f38268f70a07fa06b6abd1d76cb6881e2fb47958eb8045d3f984
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
36f91e78-0038-4978-a416-f85b072b593841154ab2-eb2a-4712-ac27-148fd4469324489236bb-3475-4ac2-9bf8-7f91592f7ad4678ead29-276b-44b6-8d07-6c455e02518cvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-57d551f18f44e8d3873b139bff1d5a2db2f13c717b3d0295e687bd95ab213fac
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
207cf2c6-4910-4b4b-aea9-cae168700efa21ef6b9b-e903-46d6-a34a-d8b3dde18eddf3ce5672-c404-4026-8d63-5a40aa9f33bcvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-583c249d07c75729c6975834fa1025fe7d381b5848feb1aa03d02a365aaf6488
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
03e1ef15-d448-44b9-9da6-e0d7c27a4e80d30a502d-a145-401e-b636-db9bbcef06caddb6b9d0-7ece-44cd-aecb-372f628c4a30fca2fd96-8adb-43b7-889b-e592b22c3584vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-5d00280b7e61e03519c1b83650a5d87f654dd625a18111d908ab01d840aacb09
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
906ea52a-598a-4a37-ad7d-3a83d2424f84966a08d3-c06a-4ea5-b933-545c639e1322vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-61e478de61e41c69453ce682831f19e397da7c841b4f820e06d8d4a68fa2ec9b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
255554b5-5c5e-4e78-9613-5f510d8bf56071685949-b97f-4b13-a843-d607bdfff0b5d604a23e-87fa-4a09-8c79-47001bf5b794eba49fba-b280-4d27-80ea-4a10fbc511efvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-6bac5e5dc0babe5d628e246786e711716ddfb068132218ad0dd5123beb466ec4
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
679440ad-c0b8-4880-bd5b-27a132b0c8b2vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-7120df83a9b73aae2817084ac2070ecc7d1fbfcada23076a424824e660688aae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
12a12400-1b61-4cf0-a5a4-b17cb1fa94dfbed3703c-021a-42c5-9859-b0a2b736f301fb72e2f7-3bcb-4ae6-8308-071be181416fvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-72194eb69952d9519f325006ffebfb4101503889dc70b262bb3ce2ae0ce452a2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
767f4044-53b3-4489-a323-2a4716593b60vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-7622e4e001e04d07e68c37d95f4e8879bc2e631632b5d522e6504407a3f05f79
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8988827a-d053-4c75-b0aa-9c30f65f61a98c75c94e-904e-493a-b7e0-2e4934dc39a7vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-7744ccbcd8b62a3ac1f4418de6eb0aa032258e4ecfa917b191c1e0094cc6ca9b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
397223c0-fb4c-40c1-9228-3a12be8349064e8528d5-b319-4da8-aed6-12967af9df8dvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-794e37fda632c2a45a36473cbb3be31a77af276763c44128eea6fbafba1fc418
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c8c7c2fa-71df-4bf5-8051-4d20ab8074eevendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-79c39923ad359eddc9f5b7de16c6ab4823d9fc2a83f182fbae06a6968653fbb3
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
759589c0-71eb-400b-a626-9509e17f8ee5vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
01192320-f99d-48ff-b59f-4ef3cb424180694c8afd-b063-4c43-b34b-b109cea274198c3beaf6-9588-4e88-a03f-ffc991827021c0ee5255-d2d9-4be1-ad28-f5706262d169vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8db20157ede2f731f576213a7e555a24d2424bb17aed8e43ad9b77c3587f9dea
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
34d77f83-04ee-4662-adaa-f280d6a82753b4d577f8-3fb1-428b-bb49-0b0c8a973b40vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-96fd4aeba8f0231e1d0f6ca7ae786e70d484258209c2dd2c10b095c6d07c6180
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c2f60267-163c-4475-b8dd-66c222064c0cvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-97b8db65c678f6a8f36811670c4d788f6a86e3041899c5a507c6cb04922f8b99
- Source class
- Nvd cpe vulnerable target
- Assertions
- 6
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1bbd8ae0-9f40-47e0-9a81-5f34cd81af511cb7280d-488f-44fc-bdf8-a0a202197928346e3576-89a7-4dbc-98b9-d7b39761306d3598c98d-4e6d-421a-86c1-fbb0e4c33c3a7e256115-b86d-4a30-a926-24feaca87b7df33904e8-d71d-489d-b5b0-9e1b2d8b2302vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-9b45fbecab58751fca5da875ab85e9592dc8183d7ca3ef52fcff184df2cbdcff
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0da524e7-a1b2-4061-bd5c-55dcca5a3be4ea92b867-e63f-49e1-923d-0eda54e2a693vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-9c0e8801dcbc8bda2b65a859db6ec37c20c470526cadcd2b4c048895c76d0c02
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
bdbe609e-27e6-40bd-83f8-356a1a74056add2ed457-aa34-4b42-9cf1-463d867f5aaavendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-9c24c965edf74248d6e6c4a32705790ac6aed2a1d1df28dd2620aa229124c509
- Source class
- Nvd cpe vulnerable target
- Assertions
- 7
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1f6e6e29-0268-40b2-afa9-14c6f0e07477af8d7bca-e935-4596-9b1f-12be8ef22f36d0c36bda-d760-4535-97d2-163e18f36866d4f4ad92-bda4-4011-8e63-b80083548276dfb4eca6-43fd-4fd1-8f18-292b346cc21de7e26c41-245b-4fa6-b205-8257ed7571d7f29c2779-1482-4468-9903-4eda554f4befvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-9ff3bc0adcc5343851d69d4a833815e08f0c8d24134495b38f50fdf38d2f17b2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
25e977a3-d94c-45b4-a78a-f30a2d69795049f482ea-467a-4ca0-b14c-c4672a408d86a102f585-e56f-495f-b1ea-8d73b1764b86e08f190e-7872-4e7d-9a26-8a2fdfac81e4vendor-c57a6167e95991f72f9616ac32b40463ac13c5f4929fcce3efc058b09a445b54 · product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
36c4ef56-c59a-4a70-9f37-86068bc22f556d2cfb99-eb25-48d7-85fa-79257ccb32ef7ccf252f-4ec4-4800-bae1-93ebab8a68bbab624a2a-a141-4b49-82ca-cff305c55ac5vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-a3ee6e9aad325f4582e56f47f80e10ac773b295ac08b0f810dbc94297c412a26
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ac5505c2-d341-4fee-b9e7-296df7f280bbvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-a6330a6e1b4583d0282fe2fd33d94aa7e7b7b51db5d5f700934b5df1d0a7474b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9fd6761e-a3a6-4ad2-9273-2c12d603482bfaf4b40d-b438-41fd-b27e-fb34b3f86101vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-a6bffb301eb198294ecf3f2cf09cb4f7bc26e3320bac15bd2a4abfe4283dd284
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
148db8cb-041f-4610-8848-4fd22af864aevendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-afac260708bb4bb1a51e28ce6b95f0356203366f8c8ffd2c790c3109033fc4fd
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c2ea42be-0f20-4d07-846c-8fc5f7331f24vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-b2aa744c9fb2b4ef0e3b842acbf37879ad4ac43af291292cfb0906170b204ab9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
39b23873-9109-4578-ad86-3e31e152510ead9f66c7-45f9-4cca-a332-d3d3c6584046vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-b3f526281daf91bf620cb4d3f23e188a98a1facc5a692614e4acbca718a32422
- Source class
- Nvd cpe vulnerable target
- Assertions
- 8
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0469c903-c500-4996-984e-1eb6e777de0a0b7b709b-2eaf-4527-96db-2377fa366de10f5d0a43-0b27-4f0c-8e1a-09e32967ff104e6ce5a1-22d6-4bbd-aa6e-34f467ec7a099f8e71a8-a387-4b75-b6aa-3f73c784ced5b41e534a-95b1-4220-a4dd-42bca336e168ca413185-e838-459d-a033-fc912bc760c6fe1f8f22-e09e-447e-8f04-543e2b75083evendor-8771dac0ae5eeec984ca23e4bbe5a243fb7896ad7c1c4afc6acd3abe53fdd152 · product-b4642eb973ddbe1a3e24c089bf036c528ab40d12c3eab0fae6fd551615375441
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
55944c76-d9e2-42c6-852c-f53a535cdce459ad3261-0fed-444a-b84b-0bf825673118704e326b-a908-4ec0-bd9f-c7ec7b1c12c57634a148-56d5-40a4-8b07-fccc60a75626vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-ba2f6e9f72c1209c147c5ead6bbf71a825fad4347275bbe719bc9a5db936c36c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
034f59ad-ceb8-44f1-8737-385ed3f08526f7ccbb3d-7ffd-4959-925a-5a2b0df59846vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-bc6ac9f1e87a668175a638bad6013a05d2210c8abe7977a8f8f0948257ba71da
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3ce18f55-3c7c-4d18-980d-986bd0ce939c990ddd99-34bf-436f-803b-80a99d96c861e193d428-6c00-4e84-b1c6-8b0978709e57vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-c04567699fe15f01ca354326b240a6ee6547e2c9ce5ee394b481a5e585d56900
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4b1e6969-7a14-49a4-8a34-b183e20e21696e8f1857-6956-4c45-9427-43c3abd5ba27be21e2c9-990b-4393-a3c5-336e4b7cb9e2e348fdd2-dc1a-4c05-a197-0f680af09a16vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-c09e1a6c06a60f75d4f5a3a91108bcb8e8b7418b4d0bcbe56608e9eba3cd934b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7fcf5fb8-e90f-43b4-b403-6aaefa7eb3e68783d14f-c7bf-429c-9cd4-52fffcaa7119adf899f3-62cf-4c36-bb34-49024b5e239bfcbbbf52-6ab4-4ea6-8544-72856d35d6bfvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-c0c4e394afd2aeefb345651f0a2689637651230ab4c5dab159b0ec5f08d4f7d7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
02a56b37-4f55-4baa-93cb-bf0da6f91c31712e0c0d-40cb-404d-8d5a-94f0758729a88102eaed-24cd-43bd-9d39-8ef86762ac27811e8ad1-6ad1-4f90-824e-3978b86dfb1bc19cf7a0-810e-4de0-aac5-01f60bffef7evendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-ce108effb28b427c9f36e268e0fd0f5ddd67d99e6e5cf4d9ba986a10360ba9da
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
430431ef-a637-4ae9-b212-cb9ecc430bcc4c82ee7d-4a9d-4ad8-9c68-0863f89ec1f6e9c87efa-a4c5-4fb2-bbe8-d3d8532dc005vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-d01c6ee0421fbc3321008543c2e5581950beffd4af6868b9a4ce0cf3d25d9429
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4706e60d-82e6-49b8-b831-3600527c95fcvendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ebce605e64c58caa7df6a30e91702332cd8c0be8f801e44353e6350e913ec5ae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8f3aaf01-63c6-4651-aeee-cb60e0b1bdefbf3c89a0-a41e-496c-82e6-45e88b382389vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-ec6d3c870b3080b10a2d067740e484ec7d797908e7c33aef105fd5d056d0b9b7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ae97150e-4d39-41b2-a171-e1a908f211a5f80fdf4a-1613-4c1e-a558-73c52320ba6avendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-f9c015ac515cb2a7cd7207205384914e8f81f0dcb6775b4c7aec3d75dee4389b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
81966fc2-5d24-4196-bbf0-39c01214392avendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-fab9230751e41d94860bfa2eaae4ca0e74c5c60f58631aa282686d100ad4fa0b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2817304f-3577-405a-9f2f-46db0db31e3cb82dc4ad-5073-413e-a9b9-11a5e54f6f65vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-fd0893ef7253031c8ee72effb6fcc65181f9b3f5e01f8f48b6a6ab89a31380a9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2aaf730a-2ca7-4d58-a5da-f6700d32948975733a8b-c946-4f25-bab2-58d1c1e9ac07Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
06b9508e-2ab9-48d6-91f7-d5c6e4ce670fAssessments
CVSS by origin
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:M/Au:N/C:P/I:P/A:PCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 8.1
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.