Evidence dossier

CVE-2022-22963

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as…

Exploited in the wild (CISA KEV since Aug 25, 2022). NVD reports CVSS 3.1 9.8. EPSS estimates 99.9% exploit likelihood as of Aug 6, 2026.

93.694.1Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

State
PUBLISHED
Published
Apr 1, 2022
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    vmware

    Record text: In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

    Inspect raw assertion
    Field
    container
    Value
    In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 99.94% probability · 99.97th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.999390000000; percentile 0.999710000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Aug 25, 2022 · first observed Jul 19, 2026

Exploit likelihood99.94%

FIRST EPSS · score date Aug 6, 2026 · 100th percentile · first observed Aug 6, 2026

SeverityCVSS 9.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
vmwareOriginal assertion
Record text

In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.

Inspect raw assertion
Field
container
Value
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

99.94% probability · 99.97th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.999390000000; percentile 0.999710000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
47Underlying assertions
28Canonical products
47Target assertions
0Constraint assertions

Grouped from 2 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

29 scope groups

vmware · source assertedn/aSpring Cloud FunctionDirect source scope
Affected: Spring Cloud Function versions 3.1.6, 3.2.2 and all old and unsupported versions
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "Spring Cloud Function versions 3.1.6, 3.2.2 and all old and unsupported versions"}]
NVD CPE · APPLICATIONoraclebanking_branchVulnerable target · 1 assertions
Version 14.5Canonical identity product-e096ebbfbc68867cd7818a6362f34d14d389e58deec90dbc9463978bdb7c74aaLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:banking_branch:14.5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bae9dfca-e0c2-420d-86d7-5593f12ee945
NVD CPE · APPLICATIONoraclebanking_cash_managementVulnerable target · 1 assertions
Version 14.5Canonical identity product-b7f87d6182eacd57ee3093c4872aa85a4198711d9cdc88f498d96b46c05036a7Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:banking_cash_management:14.5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    626c6209-8bc3-4954-bf0c-51500582457e
NVD CPE · APPLICATIONoraclebanking_corporate_lending_process_managementVulnerable target · 1 assertions
Version 14.5Canonical identity product-2039a212a3dba6e104b965b074d52559eeec0d506ad5f3df8798ca23ae35c7c5Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:banking_corporate_lending_process_management:14.5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6ee231c5-8bf0-48f4-81ef-7186814664ca
NVD CPE · APPLICATIONoraclebanking_credit_facilities_process_managementVulnerable target · 1 assertions
Version 14.5Canonical identity product-490f77d7e6e8fc39fb40c0d19e40750ab374cf78cee2f467a76ef6e126d68382Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:banking_credit_facilities_process_management:14.5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2aa5ff83-b693-4dab-b585-0fd641266231
NVD CPE · APPLICATIONoraclebanking_electronic_data_exchange_for_corporatesVulnerable target · 1 assertions
Version 14.5Canonical identity product-8ec5fcb479305f8d14419a1f0143d090c7daa93611ea8e6e4ad31448467b14c6Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:banking_electronic_data_exchange_for_corporates:14.5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a6b6968a-9eb3-46b6-9bd4-735efed3f869
NVD CPE · APPLICATIONoraclebanking_liquidity_managementVulnerable target · 2 assertions
Version 14.2; Version 14.5Canonical identity product-7efef71ffc2345e9ed82a2234c6290c377043d2058ea572cd687c93896203168Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:banking_liquidity_management:14.5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9d5a1417-2c59-431f-bf5c-a2bcfebc95fd
  2. cpe:2.3:a:oracle:banking_liquidity_management:14.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b7fc2bf9-b6d7-420e-9cf5-21ab770b9cc1
NVD CPE · APPLICATIONoraclebanking_originationVulnerable target · 1 assertions
Version 14.5Canonical identity product-57381eede567912fc90ac45fc439c21edf6c765f11fb466cf570b022ff98b6efLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:banking_origination:14.5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1d6889dd-d320-470c-ba94-165ac79a3ad2
NVD CPE · APPLICATIONoraclebanking_supply_chain_financeVulnerable target · 1 assertions
Version 14.5Canonical identity product-3a1164f432d6ba55cc8c6f4857fbab8fec6c0791860ffe2a5d27468f2604ae8dLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:banking_supply_chain_finance:14.5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    45ab3a29-0994-46f4-8093-b4a9ce0bd95f
NVD CPE · APPLICATIONoraclebanking_trade_finance_process_managementVulnerable target · 1 assertions
Version 14.5Canonical identity product-f5123e8ac4171ab8a43e2c7be8f77c760a2d17d3d31723048351f79755390b1fLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:banking_trade_finance_process_management:14.5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    aa4a9041-b9bc-451c-b1bd-4e2fd795bf27
NVD CPE · APPLICATIONoraclebanking_virtual_account_managementVulnerable target · 1 assertions
Version 14.5Canonical identity product-f44af757a5184b74e22d9444052d9bf46217674f13a132716f3892dcf69765d5Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:banking_virtual_account_management:14.5:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e2696cd1-9514-405d-a3b3-8308ec1fa571
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_automated_test_suiteVulnerable target · 2 assertions
Version 1.9.0; Version 22.1.0Canonical identity product-2df9a6c32a69a473630d1002e16384828fb2dfd0bd0fe63d33dbead65a380413Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a4ca84d6-f312-4c29-a02b-050fcb7a902b
  2. cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:22.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2df6c109-e3d3-431c-8101-2ff88763cf5a
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_consoleVulnerable target · 2 assertions
Version 1.9.0; Version 22.1.0Canonical identity product-01043ab8863c950f08a5140b64843c7d6214d4310de5e8b143fadd00a025cdd0Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_cloud_native_core_console:22.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b5bb2213-08e7-497f-b672-556fd682d122
  2. cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    daab7154-4de8-4806-86d0-c1d33b84417b
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_network_exposure_functionVulnerable target · 1 assertions
Version 22.1.0Canonical identity product-ae74202c9cdf761f961de88dab1f78c91dd57134e1263a67eefc984186d67859Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:22.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e24426ee-6a3f-413e-a70a-fb98ccd007a1
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_network_function_cloud_native_environmentVulnerable target · 3 assertions
Version 1.10.0; Version 22.1.0; Version 22.1.2Canonical identity product-9ce2d2941c587c57bce4542254ac78ecb3a7d200832d68c79ec01a96d6dbd33dLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:22.1.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1e3221bb-e48e-4b28-b84f-c888ee802a17
  2. cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.10.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c2a5b24d-bdf2-423c-98ea-a40778c01a05
  3. cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:22.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    04e6c8e9-2024-496c-9bfd-4548a5b44e2e
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_network_repository_functionVulnerable target · 2 assertions
Version 1.15.0; Version 22.1.0Canonical identity product-75c5a7c123633bc487c0b67db5d476ad5d5f58a8838a428cf0d38f32b1071c37Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6f60e32f-0ca0-4c2d-9848-cb92765a9acb
  2. cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:22.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b61a7946-f554-44a9-9e41-86114e4b4914
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_network_slice_selection_functionVulnerable target · 2 assertions
Version 1.8.0; Version 22.1.0Canonical identity product-f790488478c9b93947c419cde83308855104b3cb350de53c91c7bbc2ba41d1c2Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:22.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d6577f14-36b6-46a5-a1b1-fccada61a23b
  2. cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3aa09838-bf13-46ac-bb97-a69f48b73a8a
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_policyVulnerable target · 3 assertions
Version 1.15.0; Version 22.1.0; Version 22.1.3Canonical identity product-4906a179e2e22d81b3662b3c3400d77ff228001efb0bd2788c20df60ade3ecf4Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b4367d9b-bf81-47ad-a840-ac46317c774d
  2. cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0425918a-03f1-4541-bdef-55b03e07e115
  3. cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.1.3:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4b0c905a-ea99-4b4e-a350-7f6a63cd6eb1
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_security_edge_protection_proxyVulnerable target · 2 assertions
Version 1.7.0; Version 22.1.0Canonical identity product-fccce0827ed00a3fd1d24f8035017717d00054f35b043380f991f1f4ed03e869Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.7.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bd4349fe-eef8-489a-8abf-5fcd55ec6de0
  2. cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:22.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 27
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d235b299-9a0e-44ff-84f1-2ffbc070a21d
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_unified_data_repositoryVulnerable target · 2 assertions
Version 1.15.0; Version 22.1.0Canonical identity product-1abb2b31f7a04dc2ab0018e61daadf757aa59f886a72f5ee129978998b2a8b0aLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.15.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c6eaa723-2a23-4151-930b-86acf9cc1c0c
  2. cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:22.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 29
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3c2e50b0-64b6-4696-9213-f5d9016058a5
NVD CPE · APPLICATIONoraclecommunications_communications_policy_managementVulnerable target · 1 assertions
Version 12.6.0.0.0Canonical identity product-0c03306a23c35b21a07fad5c5bfc5ae239b3fc2fbc0bb0fb8bf102c63b1fc9dfLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:communications_communications_policy_management:12.6.0.0.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 30
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    570db369-a31b-4108-a7fd-09f674129603
NVD CPE · APPLICATIONoraclefinancial_services_analytical_applications_infrastructureVulnerable target · 2 assertions
Version 8.1.1.0; Version 8.1.2.0Canonical identity product-ba2f6e9f72c1209c147c5ead6bbf71a825fad4347275bbe719bc9a5db936c36cLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 31
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3cc69cf0-6269-40f5-871b-16cfd5ec4c45
  2. cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.2.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 32
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    172bece8-9626-4910-aaa1-a2fa9c7139e3
NVD CPE · APPLICATIONoraclefinancial_services_behavior_detection_platformVulnerable target · 3 assertions
Version 8.1.1.0; Version 8.1.1.1; Version 8.1.2.0Canonical identity product-58945c34e5ed1dcdf92cae88d718b4d617dea2549ec05647c1621b929370ffbeLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 33
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a4b3a10e-70a8-4332-8567-06ae2c45d3c6
  2. cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.1.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 34
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    059f0d4e-b007-4986-ab95-89f11147cb2b
  3. cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.2.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 35
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6cac78ad-86bb-4f06-b8cf-8e1329987f2f
NVD CPE · APPLICATIONoraclefinancial_services_enterprise_case_managementVulnerable target · 3 assertions
Version 8.1.1.0; Version 8.1.1.1; Version 8.1.2.0Canonical identity product-de3dd2ee460e007361972dc229e47ae95bf4558fd9a5594075335ea80cfe25f0Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.1.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 37
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fca5dc3f-e7d8-45e3-8114-2213ec631cdf
  2. cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 36
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    44563108-ad89-49a0-9fa5-7de5a5601d2c
  3. cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.2.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 38
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    078aefc0-96da-4f50-be8e-8360718103a5
NVD CPE · APPLICATIONoraclemysql_enterprise_monitorVulnerable target · 1 assertions
Any version (unconstrained) (<= 8.0.29)Canonical identity product-57d551f18f44e8d3873b139bff1d5a2db2f13c717b3d0295e687bd95ab213facLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 39
    Logic
    OR
    Version bounds
    through including 8.0.29
    Match ID
    b0ebac6d-d0ce-42a1-aea0-2d50c8035747

Affected-product evidence

Accepted scope and product mapping

28 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-01043ab8863c950f08a5140b64843c7d6214d4310de5e8b143fadd00a025cdd0

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
320f2019-d9df-4cc0-a439-499aba3bb29f5c8d72f5-58dc-4acb-ad90-99dbb46c2772
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-0c03306a23c35b21a07fad5c5bfc5ae239b3fc2fbc0bb0fb8bf102c63b1fc9df

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
93deeb0c-6eee-4a8f-b421-c3e4457c5a48
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-1abb2b31f7a04dc2ab0018e61daadf757aa59f886a72f5ee129978998b2a8b0a

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
74008a5a-ed43-40e7-aeed-4300437aa9e8960e18a8-ed6d-44c3-9805-c2a01363b875
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-2039a212a3dba6e104b965b074d52559eeec0d506ad5f3df8798ca23ae35c7c5

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
9b871115-89c9-4b62-8188-7cdded9317fd
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-2df9a6c32a69a473630d1002e16384828fb2dfd0bd0fe63d33dbead65a380413

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
223ed10e-6b5d-465e-9a2d-c4f67bd77efb483a5a75-0613-4847-8413-6e2c9ff6c23e
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-3a1164f432d6ba55cc8c6f4857fbab8fec6c0791860ffe2a5d27468f2604ae8d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
22eb38cf-cc4f-4073-bc49-c33a8d849c45
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-4074453fd17dd84726e7e2722aaa2ca5f508fb2322949df8628cbd14058e75aa

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5d3e1338-ec63-428f-a735-c57cb308c87f669a6226-4643-4d58-a830-97e48d13b7c2
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-4906a179e2e22d81b3662b3c3400d77ff228001efb0bd2788c20df60ade3ecf4

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
12e70290-8c78-4f2e-ac1b-1abb4f6c84cb15455607-7809-4efc-a412-6e1940c05d8024cb9e4a-209b-4f99-b660-b4e23281eb07
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-490f77d7e6e8fc39fb40c0d19e40750ab374cf78cee2f467a76ef6e126d68382

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
20d8cd33-d538-4c2c-bb6b-853e8ae3e6c4
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-57381eede567912fc90ac45fc439c21edf6c765f11fb466cf570b022ff98b6ef

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
40f253c4-3933-4974-b15a-4762fbba7087
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-57d551f18f44e8d3873b139bff1d5a2db2f13c717b3d0295e687bd95ab213fac

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
936d76f3-781c-426c-9a12-c5d0725de97c
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-58945c34e5ed1dcdf92cae88d718b4d617dea2549ec05647c1621b929370ffbe

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
17e98fe0-9889-44cf-8bc7-200ec40bde614c60fc06-ef5f-46f8-bc28-a8f5dd2415ca82fe86fe-94aa-4935-ac15-895db0766373
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-75c5a7c123633bc487c0b67db5d476ad5d5f58a8838a428cf0d38f32b1071c37

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
679b8920-bdd2-46c5-86c0-f79b053a995fd8e2c98c-21e5-41a0-81ad-b08a48b50150
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-7efef71ffc2345e9ed82a2234c6290c377043d2058ea572cd687c93896203168

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
53da3572-8307-4d31-9783-d9e9e7ae332f660f2c81-b1eb-42f1-be72-754f0f300f7e
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-8ec5fcb479305f8d14419a1f0143d090c7daa93611ea8e6e4ad31448467b14c6

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2792bd2c-7258-4bda-ab60-0657ed60b2cc
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-96140747cd8caa2367bbc11701cfd3a965a31bf6eaecb69bda4a18768dbfda10

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
381ac582-4433-41d3-bacc-5affa39d915a
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-9ce2d2941c587c57bce4542254ac78ecb3a7d200832d68c79ec01a96d6dbd33d

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
378bce48-a934-4404-b8ad-349a2982172947e96861-20c7-4f00-8790-741c49b4040c65c378eb-06f6-4ed2-85e3-a69ccf4be534
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-ae74202c9cdf761f961de88dab1f78c91dd57134e1263a67eefc984186d67859

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3a4ce5db-5d7b-4e53-ab73-2f25a71dbd5c
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-b7f87d6182eacd57ee3093c4872aa85a4198711d9cdc88f498d96b46c05036a7

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
338768a2-8971-4005-9e22-9739508fbc45
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-ba2f6e9f72c1209c147c5ead6bbf71a825fad4347275bbe719bc9a5db936c36c

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
17aa2177-a32b-4fd1-a9a3-ab68a4a623271a7d5d99-0b95-43d5-82c2-0b1edbba842c
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-c04567699fe15f01ca354326b240a6ee6547e2c9ce5ee394b481a5e585d56900

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1c6c25e8-1546-4789-b9f1-63e652ac6f30cdf6d0cf-0a43-4898-8a91-c324090b41de
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-de3dd2ee460e007361972dc229e47ae95bf4558fd9a5594075335ea80cfe25f0

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2bb5b7af-582c-4a59-bd2b-3372e03364ff45560748-337c-4301-a589-367cd246eb4dd16a1a45-7c08-4f98-8063-af1fcf93eaf8
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-e096ebbfbc68867cd7818a6362f34d14d389e58deec90dbc9463978bdb7c74aa

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
9c9e626c-0886-432b-a1b6-694a73f191e5
Mapping establishedEvidence supported

vendor-6b310233dbc1eceadb11ae200191b71c5a499cd0c4916b064b08d7f851b21f9f · product-e2de7e0a9617a58ba0812b544c265bb96dddb6e43d2b73eaa7c46014e8730a5f

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
58148847-2ab0-4c6c-9264-d0cd5efb009d92b92210-b8d1-4941-bcc3-5a7c0cd09ec5
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-f44af757a5184b74e22d9444052d9bf46217674f13a132716f3892dcf69765d5

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5a8beb9a-9e31-4067-b69c-a78859d81ce7
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-f5123e8ac4171ab8a43e2c7be8f77c760a2d17d3d31723048351f79755390b1f

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e5add855-65e2-4638-82a6-99b6d2151bb7
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-f790488478c9b93947c419cde83308855104b3cb350de53c91c7bbc2ba41d1c2

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c0e7ad50-5188-49fd-aa70-38b16182551dfc15bed7-3dc8-4b44-9117-3acd0b5af79b
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-fccce0827ed00a3fd1d24f8035017717d00054f35b043380f991f1f4ed03e869

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
22470c38-7323-492f-ab71-c30ff33d1f22fd22c560-d03d-4c29-88cb-e8eaae710492
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
56e2e11b-c062-40dd-992e-a0444755dd48

Assessments

CVSS by origin

9.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:P/I:P/A:P
9.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

9.8Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
9.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.