Evidence dossier

CVE-2020-1938

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.

Exploited in the wild (CISA KEV since Mar 3, 2022). NVD reports CVSS 3.1 9.8. EPSS estimates 99.3% exploit likelihood as of Aug 2, 2026.

94.594.8Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.

State
PUBLISHED
Published
Feb 24, 2020
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    apache

    Record text: When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.

    Inspect raw assertion
    Field
    container
    Value
    When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Apache Tomcat Improper Privilege Management Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Apache Tomcat Improper Privilege Management Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 99.27% probability · 99.93th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.992700000000; percentile 0.999330000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Mar 3, 2022 · first observed Jul 19, 2026

Exploit likelihood99.27%

FIRST EPSS · score date Aug 2, 2026 · 99.9th percentile · first observed Aug 2, 2026

SeverityCVSS 9.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

apacheOriginal assertion
Record text

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.

Inspect raw assertion
Field
container
Value
When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It was expected (and recommended in the security guide) that this Connector would be disabled if not required. This vulnerability report identified a mechanism that allowed: - returning arbitrary files from anywhere in the web application - processing any file in the web application as a JSP Further, if the web application allowed file upload and stored those files within the web application (or the attacker was able to control the content of the web application by some other means) then this, along with the ability to process a file as a JSP, made remote code execution possible. It is important to note that mitigation is only required if an AJP port is accessible to untrusted users. Users wishing to take a defence-in-depth approach and block the vector that permits returning arbitrary files and execution as JSP may upgrade to Apache Tomcat 9.0.31, 8.5.51 or 7.0.100 or later. A number of changes were made to the default AJP Connector configuration in 9.0.31 to harden the default configuration. It is likely that users upgrading to 9.0.31, 8.5.51 or 7.0.100 or later will need to make small changes to their configurations.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Apache Tomcat Improper Privilege Management Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Apache Tomcat Improper Privilege Management Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

99.27% probability · 99.93th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.992700000000; percentile 0.999330000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
38Underlying assertions
21Canonical products
38Target assertions
0Constraint assertions

Grouped from 7 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

22 scope groups

apache · source assertedApacheApache TomcatDirect source scope
Affected: Apache Tomcat 9.0.0.M1 to 9.0.0.30Affected: 8.5.0 to 8.5.50Affected: 7.0.0 to 7.0.99
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "Apache Tomcat 9.0.0.M1 to 9.0.0.30"}, {"status": "affected", "version": "8.5.0 to 8.5.50"}, {"status": "affected", "version": "7.0.0 to 7.0.99"}]
NVD CPE · APPLICATIONapachegeodeVulnerable target · 1 assertions
Version 1.12.0Canonical identity product-08b72c37d04657490f3c191f03638d1bddaef87d05bb21f618db5d47c21857b0Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:apache:geode:1.12.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8dd32c20-8b17-4197-9943-b8293d1c3bed
NVD CPE · APPLICATIONapachetomcatVulnerable target · 3 assertions
Any version (unconstrained) (>= 7.0.0, < 7.0.100); Any version (unconstrained) (>= 8.5.0, < 8.5.51); Any version (unconstrained) (>= 9.0.0, < 9.0.31)Canonical identity product-b4642eb973ddbe1a3e24c089bf036c528ab40d12c3eab0fae6fd551615375441Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 9.0.0; through excluding 9.0.31
    Match ID
    50efbdf6-932e-40dd-9229-5a9c239cc011
  2. cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 7.0.0; through excluding 7.0.100
    Match ID
    e7d96045-5a8b-46dd-9f3b-f383f95597e6
  3. cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 8.5.0; through excluding 8.5.51
    Match ID
    de0ea2b0-2cdd-4f86-ae16-63c774803783
NVD CPE · APPLICATIONblackberrygood_controlVulnerable target · 1 assertions
Any version (unconstrained) (<= 5.2.58.38)Canonical identity product-5ecad6231b6c932ae7b8e0c5a2e23406e7ba2568755a6f7a52265e351433d2f5Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:blackberry:good_control:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    through including 5.2.58.38
    Match ID
    f028aaeb-7536-4e9c-a2f6-0161191beef2
NVD CPE · APPLICATIONblackberryworkspaces_serverVulnerable target · 4 assertions
Version 7.0.1; Version 7.1.2; Version 8.1.0; Version 9.0Canonical identity product-1120fcce96f23cdbae05d5da6a6ebf69e1ba4ad11987ef51ecacd50bc1742c3eLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:blackberry:workspaces_server:8.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    284bd023-c583-4ba8-8ea9-7a153dcd45dd
  2. cpe:2.3:a:blackberry:workspaces_server:7.0.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6b8a0865-a3c5-40fb-86c1-dfd9babc1d16
  3. cpe:2.3:a:blackberry:workspaces_server:7.1.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d669a2cd-0be2-4b90-bf94-58d69512fe94
  4. cpe:2.3:a:blackberry:workspaces_server:9.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    834c9378-9be8-4250-bcf0-43780f6a1ef7
NVD CPE · OPERATING SYSTEMdebiandebian_linuxVulnerable target · 3 assertions
Version 10.0; Version 8.0; Version 9.0Canonical identity product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c11e6fb0-c8c0-4527-9aa0-cb9b316f8f43
  2. cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    07b237a9-69a3-4a9c-9da0-4e06bd37ae73
  3. cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    deece5fc-cacf-4496-a3e7-164736409252
NVD CPE · OPERATING SYSTEMfedoraprojectfedoraVulnerable target · 3 assertions
Version 30; Version 31; Version 32Canonical identity product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    36d96259-24bd-44e2-96d9-78ce1d41f956
  2. cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    97a4b8df-58da-4ab6-a1f9-331b36409ba3
  3. cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    80f0fa5d-8d3b-4c0e-81e2-87998286af33
NVD CPE · APPLICATIONnetappdata_availability_servicesVulnerable target · 1 assertions
Version not applicableCanonical identity product-18d0274b62b5dbcc718af15dbb7374bdc33e99c5560c2b066ea58196a4eeca23Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:netapp:data_availability_services:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0ef46487-b64a-454e-aecc-d74b83170acd
NVD CPE · APPLICATIONnetapponcommand_system_managerVulnerable target · 1 assertions
Any version (unconstrained) (>= 3.0.0, <= 3.1.3)Canonical identity product-3db18bc6b8ab9c044c383d7df0a90023d0b870d1ab18b593378eb054160b5167Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:netapp:oncommand_system_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 3.0.0; through including 3.1.3
    Match ID
    34b80c9d-62aa-42fa-ab46-f8a414fcbe5e
NVD CPE · OPERATING SYSTEMopensuseleapVulnerable target · 1 assertions
Version 15.1Canonical identity product-c27aedc6088fe47e75f3a72d532ce7dcfb4a151fd6deaeecc763cf1d10026925Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b620311b-34a3-48a6-82df-6f078d7a4493
NVD CPE · APPLICATIONoracleagile_engineering_data_managementVulnerable target · 1 assertions
Version 6.2.1.0Canonical identity product-9586a2db2c66a15d4bcf82ad70726953c6712a6ede02c9d1196a5346bf71a89eLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    80c9dbb8-3d50-4d5d-859a-b022eb7c2e64
NVD CPE · APPLICATIONoracleagile_plmVulnerable target · 3 assertions
Version 9.3.3; Version 9.3.5; Version 9.3.6Canonical identity product-61e478de61e41c69453ce682831f19e397da7c841b4f820e06d8d4a68fa2ec9bLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ed43772f-d280-42f6-a292-7198284d6fe7
  2. cpe:2.3:a:oracle:agile_plm:9.3.3:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d14abf04-e460-4911-9c6c-b7bcefe68e9d
  3. cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c650fedb-e903-4c2d-ad40-282ab5f2e3c2
NVD CPE · APPLICATIONoraclecommunications_element_managerVulnerable target · 3 assertions
Version 8.1.1; Version 8.2.0; Version 8.2.1Canonical identity product-1a9306a675712fb96b99645849deb869b89fddeb3e9b691d56df3ce1604e6fe5Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_element_manager:8.2.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4f1d64bc-17bf-4dae-b5fc-bc41f9c12dfd
  2. cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0c57fd3a-0cc1-4ba9-879a-8c4a40234162
  3. cpe:2.3:a:oracle:communications_element_manager:8.2.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    698fb6d0-b26f-4760-9b9b-1c65fbff2126
NVD CPE · APPLICATIONoraclecommunications_instant_messaging_serverVulnerable target · 1 assertions
Version 10.0.1.4.0Canonical identity product-03e952e5feb49cbab6d67785e54883eca72c93fde4ee0531366703d67c7f92f5Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.4.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0db23b9a-571e-4b77-b432-23f3dc9b67d1
NVD CPE · APPLICATIONoraclehealth_sciences_empirica_inspectionsVulnerable target · 1 assertions
Version 1.0.1.2Canonical identity product-0c2e4bc5085e04c17e1c18fc8c10b5f73cf112ccd8fce369b4fbe4c9e43d5835Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:health_sciences_empirica_inspections:1.0.1.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f5f58398-0001-42fe-bd17-44f924955c3d
NVD CPE · APPLICATIONoraclehealth_sciences_empirica_signalVulnerable target · 1 assertions
Version 7.3.3Canonical identity product-5025f956b7b2fd711ae9c6af11bbb53854b018692a8e5379cbbcb8878ea56f06Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:health_sciences_empirica_signal:7.3.3:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    456ae11c-dd5b-4ea9-aa93-aafc988830eb
NVD CPE · APPLICATIONoraclehospitality_guest_accessVulnerable target · 2 assertions
Version 4.2.0; Version 4.2.1Canonical identity product-7744ccbcd8b62a3ac1f4418de6eb0aa032258e4ecfa917b191c1e0094cc6ca9bLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1a3dc116-2844-47a1-bec2-d0675dd97148
  2. cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e0f1df3e-0f2d-4efc-9a3e-f72149c8ae94
NVD CPE · APPLICATIONoracleinstantis_enterprisetrackVulnerable target · 1 assertions
Any version (unconstrained) (>= 17.1, <= 17.3)Canonical identity product-5d00280b7e61e03519c1b83650a5d87f654dd625a18111d908ab01d840aacb09Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:instantis_enterprisetrack:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 12
    Logic
    OR
    Version bounds
    from including 17.1; through including 17.3
    Match ID
    9a74fd5f-4fea-4a74-8b92-72dfde6ba464
NVD CPE · APPLICATIONoraclemysql_enterprise_monitorVulnerable target · 2 assertions
Any version (unconstrained) (<= 4.0.12); Any version (unconstrained) (>= 8.0.0, <= 8.0.20)Canonical identity product-57d551f18f44e8d3873b139bff1d5a2db2f13c717b3d0295e687bd95ab213facLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 13
    Logic
    OR
    Version bounds
    through including 4.0.12
    Match ID
    9a3bbe71-ca00-4f54-9210-fc7572c87cfb
  2. cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 14
    Logic
    OR
    Version bounds
    from including 8.0.0; through including 8.0.20
    Match ID
    73573516-eda0-4176-a3ed-2f7006c87f8e
NVD CPE · APPLICATIONoraclesiebel_ui_frameworkVulnerable target · 1 assertions
Any version (unconstrained) (<= 20.5)Canonical identity product-2be12cf227ce7793af4c98032a8664c048b64bfb523587e57d3ca7f439e0a123Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:siebel_ui_framework:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 15
    Logic
    OR
    Version bounds
    through including 20.5
    Match ID
    f510ed6d-7bf8-4548-bf0f-3cf926eb135e
NVD CPE · APPLICATIONoracletransportation_managementVulnerable target · 1 assertions
Version 6.3.7Canonical identity product-9c24c965edf74248d6e6c4a32705790ac6aed2a1d1df28dd2620aa229124c509Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:transportation_management:6.3.7:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a58642e0-ca59-4de6-a83c-f551fc621c32
NVD CPE · APPLICATIONoracleworkload_managerVulnerable target · 3 assertions
Version 12.2.0.1; Version 18c; Version 19cCanonical identity product-41c5cb18a55dd692691af6f4e4224d4919937f66d2f26def7a1ccb9123341fbbLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:workload_manager:18c:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    630c8e99-fe49-486e-9003-40b82809b7a3
  2. cpe:2.3:a:oracle:workload_manager:19c:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c842de9e-5e12-4295-afa5-deb5fede490a
  3. cpe:2.3:a:oracle:workload_manager:12.2.0.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ad848fe1-cfd7-490c-b008-df3b30f3256f

Affected-product evidence

Accepted scope and product mapping

21 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-03e952e5feb49cbab6d67785e54883eca72c93fde4ee0531366703d67c7f92f5

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
330e2f9d-61d9-44cc-a36c-6bdc09804ba2
Mapping establishedEvidence supported

vendor-8771dac0ae5eeec984ca23e4bbe5a243fb7896ad7c1c4afc6acd3abe53fdd152 · product-08b72c37d04657490f3c191f03638d1bddaef87d05bb21f618db5d47c21857b0

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e7f8348b-49dd-416f-b28a-1b6de30d4190
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-0c2e4bc5085e04c17e1c18fc8c10b5f73cf112ccd8fce369b4fbe4c9e43d5835

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
28966f01-5423-4ef8-abfa-e4a803b059b1
Mapping establishedEvidence supported

vendor-345a612fc97ecd07f15ee9d982c3f402b3f30ef1b40abfacbec4f13c88fe38cf · product-1120fcce96f23cdbae05d5da6a6ebf69e1ba4ad11987ef51ecacd50bc1742c3e

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
467f7aa4-c9b3-43d7-ad8a-bc1170573ec24803fa10-bda2-415b-a72f-504c971e330d48e82321-0637-4148-90cb-6a964dab4ac0a5f93b32-33c7-461c-b27b-a96ac717075a
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-18d0274b62b5dbcc718af15dbb7374bdc33e99c5560c2b066ea58196a4eeca23

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e0ce1b1a-c373-4c19-b601-2b7a1a230639
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-1a9306a675712fb96b99645849deb869b89fddeb3e9b691d56df3ce1604e6fe5

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
6872fb3d-1508-45fc-a86f-600d1f3b1f7fa3b46179-1f89-48bc-8d13-ed2cbe37706fd7f089cd-d0ed-4a40-85fb-578f296ce8dc
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-2be12cf227ce7793af4c98032a8664c048b64bfb523587e57d3ca7f439e0a123

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
37492981-a0f6-4a9a-9037-9faefa6bc1cd
Mapping establishedEvidence supported

vendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
43e3a698-5e93-4002-aa87-b68f583bcbe34922660e-70e1-4d4b-9a2c-da68bfc2d5bd9812f080-892a-4fb7-ae94-38ae762a74c0
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3db18bc6b8ab9c044c383d7df0a90023d0b870d1ab18b593378eb054160b5167

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1f7aeeaa-59f6-4a3a-a493-c3d021eec1f6
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-41c5cb18a55dd692691af6f4e4224d4919937f66d2f26def7a1ccb9123341fbb

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
6d5c72c1-ee77-4cb2-a337-5a111900d052c984802e-ee53-43cc-96d6-90406d0382cddea18013-92a3-4038-ac6f-8808fca3ac11
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-5025f956b7b2fd711ae9c6af11bbb53854b018692a8e5379cbbcb8878ea56f06

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
8437d75f-48fa-4592-83dd-33427b6b87da
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-57d551f18f44e8d3873b139bff1d5a2db2f13c717b3d0295e687bd95ab213fac

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
36e9b712-d4a8-4ef4-bd1a-79f8ead99828dab966c9-650b-482e-8007-f48b95357100
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-5d00280b7e61e03519c1b83650a5d87f654dd625a18111d908ab01d840aacb09

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
70c21d34-a42e-465a-ab56-ceadf75456bb
Mapping establishedEvidence supported

vendor-345a612fc97ecd07f15ee9d982c3f402b3f30ef1b40abfacbec4f13c88fe38cf · product-5ecad6231b6c932ae7b8e0c5a2e23406e7ba2568755a6f7a52265e351433d2f5

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1c507255-85f4-4daf-aa91-569e04f64c81
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-61e478de61e41c69453ce682831f19e397da7c841b4f820e06d8d4a68fa2ec9b

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
29df0600-5b95-492d-a209-78f6a22de66fa59913b4-caae-4bd8-bd0e-06e03a734a4bc289ea07-a328-4273-b245-ed01ff7ce444
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-7744ccbcd8b62a3ac1f4418de6eb0aa032258e4ecfa917b191c1e0094cc6ca9b

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
077658f2-45e6-4c52-900d-66a2fc351fdc343b08b8-dcff-4913-9bcc-be8cebfa8bdc
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-9586a2db2c66a15d4bcf82ad70726953c6712a6ede02c9d1196a5346bf71a89e

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e705bc55-b480-4f30-b884-a9bd5808285b
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-9c24c965edf74248d6e6c4a32705790ac6aed2a1d1df28dd2620aa229124c509

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
ca0fca04-4fd0-4637-a2ce-a003bee22ede
Mapping establishedEvidence supported

vendor-8771dac0ae5eeec984ca23e4bbe5a243fb7896ad7c1c4afc6acd3abe53fdd152 · product-b4642eb973ddbe1a3e24c089bf036c528ab40d12c3eab0fae6fd551615375441

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1817f90e-c0d6-47f8-9b01-7b042520bccf354e03ab-e572-44aa-9419-13f782cd42feb7c74932-c5b4-495f-805c-7716b2dd128d
Mapping establishedEvidence supported

vendor-f98e1750e4b030e2bb71130d14421ff255427227a8b696c92978cf6c77fc265d · product-c27aedc6088fe47e75f3a72d532ce7dcfb4a151fd6deaeecc763cf1d10026925

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e0e756ba-dd1a-4e4a-900f-db8094134d5e
Mapping establishedEvidence supported

vendor-2d566b06907460b10e6e48c8544126e19f1d6df137983056edae8d0b51e34e45 · product-c96c7662a6606ed7594747da3d7ba9ee3a9758ab11658f6a3f42616361472e47

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
01c96f10-8123-4d03-8068-8da88bc2b7b950617fad-2966-4c08-a244-47d786b6345bf0e6b090-73bc-416b-bb8e-f914416a6e2c
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
271d1e1e-6ad5-4dd8-ae6a-972dea0d8208

Assessments

CVSS by origin

9.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:P/I:P/A:P
9.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

9.8Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
9.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.