CISA KEV · catalog date Mar 3, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2020-1938
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.
Exploited in the wild (CISA KEV since Mar 3, 2022). NVD reports CVSS 3.1 9.8. EPSS estimates 99.3% exploit likelihood as of Aug 2, 2026.
As of Aug 27, 2026
Normalized restatement
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.
- State
- PUBLISHED
- Published
- Feb 24, 2020
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCAapacheOriginal evidence ↗
Record text: When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.
Inspect raw assertion
- Field
container- Value
- When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Apache Tomcat Improper Privilege Management Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Apache Tomcat Improper Privilege Management Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 99.27% probability · 99.93th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.992700000000; percentile 0.999330000000
FIRST EPSS · score date Aug 2, 2026 · 99.9th percentile · first observed Aug 2, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.
Inspect raw assertion
- Field
container- Value
- When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Apache Tomcat Improper Privilege Management Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Apache Tomcat Improper Privilege Management Vulnerability
99.27% probability · 99.93th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.992700000000; percentile 0.999330000000
Applicability
Cited product scope
Grouped from 7 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
22 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "Apache Tomcat 9.0.0.M1 to 9.0.0.30"}, {"status": "affected", "version": "8.5.0 to 8.5.50"}, {"status": "affected", "version": "7.0.0 to 7.0.99"}]product-08b72c37d04657490f3c191f03638d1bddaef87d05bb21f618db5d47c21857b0Linked exactInspect raw assertion
cpe:2.3:a:apache:geode:1.12.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8dd32c20-8b17-4197-9943-b8293d1c3bed
product-b4642eb973ddbe1a3e24c089bf036c528ab40d12c3eab0fae6fd551615375441Linked exactInspect raw assertions
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- from including 9.0.0; through excluding 9.0.31
- Match ID
50efbdf6-932e-40dd-9229-5a9c239cc011
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 7.0.0; through excluding 7.0.100
- Match ID
e7d96045-5a8b-46dd-9f3b-f383f95597e6
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 8.5.0; through excluding 8.5.51
- Match ID
de0ea2b0-2cdd-4f86-ae16-63c774803783
product-5ecad6231b6c932ae7b8e0c5a2e23406e7ba2568755a6f7a52265e351433d2f5Linked exactInspect raw assertion
cpe:2.3:a:blackberry:good_control:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- through including 5.2.58.38
- Match ID
f028aaeb-7536-4e9c-a2f6-0161191beef2
product-1120fcce96f23cdbae05d5da6a6ebf69e1ba4ad11987ef51ecacd50bc1742c3eLinked exactInspect raw assertions
cpe:2.3:a:blackberry:workspaces_server:8.1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
284bd023-c583-4ba8-8ea9-7a153dcd45dd
cpe:2.3:a:blackberry:workspaces_server:7.0.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6b8a0865-a3c5-40fb-86c1-dfd9babc1d16
cpe:2.3:a:blackberry:workspaces_server:7.1.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d669a2cd-0be2-4b90-bf94-58d69512fe94
cpe:2.3:a:blackberry:workspaces_server:9.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
834c9378-9be8-4250-bcf0-43780f6a1ef7
product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exactInspect raw assertions
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c11e6fb0-c8c0-4527-9aa0-cb9b316f8f43
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
07b237a9-69a3-4a9c-9da0-4e06bd37ae73
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
deece5fc-cacf-4496-a3e7-164736409252
product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47Linked exactInspect raw assertions
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
36d96259-24bd-44e2-96d9-78ce1d41f956
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
97a4b8df-58da-4ab6-a1f9-331b36409ba3
cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
80f0fa5d-8d3b-4c0e-81e2-87998286af33
product-18d0274b62b5dbcc718af15dbb7374bdc33e99c5560c2b066ea58196a4eeca23Linked exactInspect raw assertion
cpe:2.3:a:netapp:data_availability_services:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0ef46487-b64a-454e-aecc-d74b83170acd
product-3db18bc6b8ab9c044c383d7df0a90023d0b870d1ab18b593378eb054160b5167Linked exactInspect raw assertion
cpe:2.3:a:netapp:oncommand_system_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 3.0.0; through including 3.1.3
- Match ID
34b80c9d-62aa-42fa-ab46-f8a414fcbe5e
product-c27aedc6088fe47e75f3a72d532ce7dcfb4a151fd6deaeecc763cf1d10026925Linked exactInspect raw assertion
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b620311b-34a3-48a6-82df-6f078d7a4493
product-9586a2db2c66a15d4bcf82ad70726953c6712a6ede02c9d1196a5346bf71a89eLinked exactInspect raw assertion
cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
80c9dbb8-3d50-4d5d-859a-b022eb7c2e64
product-61e478de61e41c69453ce682831f19e397da7c841b4f820e06d8d4a68fa2ec9bLinked exactInspect raw assertions
cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ed43772f-d280-42f6-a292-7198284d6fe7
cpe:2.3:a:oracle:agile_plm:9.3.3:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d14abf04-e460-4911-9c6c-b7bcefe68e9d
cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c650fedb-e903-4c2d-ad40-282ab5f2e3c2
product-1a9306a675712fb96b99645849deb869b89fddeb3e9b691d56df3ce1604e6fe5Linked exactInspect raw assertions
cpe:2.3:a:oracle:communications_element_manager:8.2.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4f1d64bc-17bf-4dae-b5fc-bc41f9c12dfd
cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0c57fd3a-0cc1-4ba9-879a-8c4a40234162
cpe:2.3:a:oracle:communications_element_manager:8.2.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
698fb6d0-b26f-4760-9b9b-1c65fbff2126
product-03e952e5feb49cbab6d67785e54883eca72c93fde4ee0531366703d67c7f92f5Linked exactInspect raw assertion
cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.4.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0db23b9a-571e-4b77-b432-23f3dc9b67d1
product-0c2e4bc5085e04c17e1c18fc8c10b5f73cf112ccd8fce369b4fbe4c9e43d5835Linked exactInspect raw assertion
cpe:2.3:a:oracle:health_sciences_empirica_inspections:1.0.1.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f5f58398-0001-42fe-bd17-44f924955c3d
product-5025f956b7b2fd711ae9c6af11bbb53854b018692a8e5379cbbcb8878ea56f06Linked exactInspect raw assertion
cpe:2.3:a:oracle:health_sciences_empirica_signal:7.3.3:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
456ae11c-dd5b-4ea9-aa93-aafc988830eb
product-7744ccbcd8b62a3ac1f4418de6eb0aa032258e4ecfa917b191c1e0094cc6ca9bLinked exactInspect raw assertions
cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1a3dc116-2844-47a1-bec2-d0675dd97148
cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e0f1df3e-0f2d-4efc-9a3e-f72149c8ae94
product-5d00280b7e61e03519c1b83650a5d87f654dd625a18111d908ab01d840aacb09Linked exactInspect raw assertion
cpe:2.3:a:oracle:instantis_enterprisetrack:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 12
- Logic
- OR
- Version bounds
- from including 17.1; through including 17.3
- Match ID
9a74fd5f-4fea-4a74-8b92-72dfde6ba464
product-57d551f18f44e8d3873b139bff1d5a2db2f13c717b3d0295e687bd95ab213facLinked exactInspect raw assertions
cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 13
- Logic
- OR
- Version bounds
- through including 4.0.12
- Match ID
9a3bbe71-ca00-4f54-9210-fc7572c87cfb
cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 14
- Logic
- OR
- Version bounds
- from including 8.0.0; through including 8.0.20
- Match ID
73573516-eda0-4176-a3ed-2f7006c87f8e
product-2be12cf227ce7793af4c98032a8664c048b64bfb523587e57d3ca7f439e0a123Linked exactInspect raw assertion
cpe:2.3:a:oracle:siebel_ui_framework:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 15
- Logic
- OR
- Version bounds
- through including 20.5
- Match ID
f510ed6d-7bf8-4548-bf0f-3cf926eb135e
product-9c24c965edf74248d6e6c4a32705790ac6aed2a1d1df28dd2620aa229124c509Linked exactInspect raw assertion
cpe:2.3:a:oracle:transportation_management:6.3.7:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a58642e0-ca59-4de6-a83c-f551fc621c32
product-41c5cb18a55dd692691af6f4e4224d4919937f66d2f26def7a1ccb9123341fbbLinked exactInspect raw assertions
cpe:2.3:a:oracle:workload_manager:18c:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 18
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
630c8e99-fe49-486e-9003-40b82809b7a3
cpe:2.3:a:oracle:workload_manager:19c:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c842de9e-5e12-4295-afa5-deb5fede490a
cpe:2.3:a:oracle:workload_manager:12.2.0.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 17
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ad848fe1-cfd7-490c-b008-df3b30f3256f
Affected-product evidence
Accepted scope and product mapping
21 canonical links · 1 source-reported links
vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-03e952e5feb49cbab6d67785e54883eca72c93fde4ee0531366703d67c7f92f5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
330e2f9d-61d9-44cc-a36c-6bdc09804ba2vendor-8771dac0ae5eeec984ca23e4bbe5a243fb7896ad7c1c4afc6acd3abe53fdd152 · product-08b72c37d04657490f3c191f03638d1bddaef87d05bb21f618db5d47c21857b0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e7f8348b-49dd-416f-b28a-1b6de30d4190vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-0c2e4bc5085e04c17e1c18fc8c10b5f73cf112ccd8fce369b4fbe4c9e43d5835
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
28966f01-5423-4ef8-abfa-e4a803b059b1vendor-345a612fc97ecd07f15ee9d982c3f402b3f30ef1b40abfacbec4f13c88fe38cf · product-1120fcce96f23cdbae05d5da6a6ebf69e1ba4ad11987ef51ecacd50bc1742c3e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 4
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
467f7aa4-c9b3-43d7-ad8a-bc1170573ec24803fa10-bda2-415b-a72f-504c971e330d48e82321-0637-4148-90cb-6a964dab4ac0a5f93b32-33c7-461c-b27b-a96ac717075avendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-18d0274b62b5dbcc718af15dbb7374bdc33e99c5560c2b066ea58196a4eeca23
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e0ce1b1a-c373-4c19-b601-2b7a1a230639vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-1a9306a675712fb96b99645849deb869b89fddeb3e9b691d56df3ce1604e6fe5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6872fb3d-1508-45fc-a86f-600d1f3b1f7fa3b46179-1f89-48bc-8d13-ed2cbe37706fd7f089cd-d0ed-4a40-85fb-578f296ce8dcvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-2be12cf227ce7793af4c98032a8664c048b64bfb523587e57d3ca7f439e0a123
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
37492981-a0f6-4a9a-9037-9faefa6bc1cdvendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
43e3a698-5e93-4002-aa87-b68f583bcbe34922660e-70e1-4d4b-9a2c-da68bfc2d5bd9812f080-892a-4fb7-ae94-38ae762a74c0vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3db18bc6b8ab9c044c383d7df0a90023d0b870d1ab18b593378eb054160b5167
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1f7aeeaa-59f6-4a3a-a493-c3d021eec1f6vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-41c5cb18a55dd692691af6f4e4224d4919937f66d2f26def7a1ccb9123341fbb
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6d5c72c1-ee77-4cb2-a337-5a111900d052c984802e-ee53-43cc-96d6-90406d0382cddea18013-92a3-4038-ac6f-8808fca3ac11vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-5025f956b7b2fd711ae9c6af11bbb53854b018692a8e5379cbbcb8878ea56f06
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8437d75f-48fa-4592-83dd-33427b6b87davendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-57d551f18f44e8d3873b139bff1d5a2db2f13c717b3d0295e687bd95ab213fac
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
36e9b712-d4a8-4ef4-bd1a-79f8ead99828dab966c9-650b-482e-8007-f48b95357100vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-5d00280b7e61e03519c1b83650a5d87f654dd625a18111d908ab01d840aacb09
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
70c21d34-a42e-465a-ab56-ceadf75456bbvendor-345a612fc97ecd07f15ee9d982c3f402b3f30ef1b40abfacbec4f13c88fe38cf · product-5ecad6231b6c932ae7b8e0c5a2e23406e7ba2568755a6f7a52265e351433d2f5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1c507255-85f4-4daf-aa91-569e04f64c81vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-61e478de61e41c69453ce682831f19e397da7c841b4f820e06d8d4a68fa2ec9b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
29df0600-5b95-492d-a209-78f6a22de66fa59913b4-caae-4bd8-bd0e-06e03a734a4bc289ea07-a328-4273-b245-ed01ff7ce444vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-7744ccbcd8b62a3ac1f4418de6eb0aa032258e4ecfa917b191c1e0094cc6ca9b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
077658f2-45e6-4c52-900d-66a2fc351fdc343b08b8-dcff-4913-9bcc-be8cebfa8bdcvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-9586a2db2c66a15d4bcf82ad70726953c6712a6ede02c9d1196a5346bf71a89e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e705bc55-b480-4f30-b884-a9bd5808285bvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-9c24c965edf74248d6e6c4a32705790ac6aed2a1d1df28dd2620aa229124c509
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ca0fca04-4fd0-4637-a2ce-a003bee22edevendor-8771dac0ae5eeec984ca23e4bbe5a243fb7896ad7c1c4afc6acd3abe53fdd152 · product-b4642eb973ddbe1a3e24c089bf036c528ab40d12c3eab0fae6fd551615375441
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1817f90e-c0d6-47f8-9b01-7b042520bccf354e03ab-e572-44aa-9419-13f782cd42feb7c74932-c5b4-495f-805c-7716b2dd128dvendor-f98e1750e4b030e2bb71130d14421ff255427227a8b696c92978cf6c77fc265d · product-c27aedc6088fe47e75f3a72d532ce7dcfb4a151fd6deaeecc763cf1d10026925
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e0e756ba-dd1a-4e4a-900f-db8094134d5evendor-2d566b06907460b10e6e48c8544126e19f1d6df137983056edae8d0b51e34e45 · product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47
- Source class
- Nvd cpe vulnerable target
- Assertions
- 3
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
01c96f10-8123-4d03-8068-8da88bc2b7b950617fad-2966-4c08-a244-47d786b6345bf0e6b090-73bc-416b-bb8e-f914416a6e2cCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
271d1e1e-6ad5-4dd8-ae6a-972dea0d8208Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:P/I:P/A:PCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.