Evidence dossier

CVE-2022-22965

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

Exploited in the wild (CISA KEV since Apr 4, 2022). NVD reports CVSS 3.1 9.8. EPSS estimates 99.7% exploit likelihood as of Jul 26, 2026.

95.395.7Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

State
PUBLISHED
Published
Apr 1, 2022
Updated
Oct 21, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    vmware

    Record text: A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

    Inspect raw assertion
    Field
    container
    Value
    A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Spring Framework JDK 9+ Remote Code Execution Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Spring Framework JDK 9+ Remote Code Execution Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 99.68% probability · 99.95th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.996770000000; percentile 0.999490000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Apr 4, 2022 · first observed Jul 19, 2026

Exploit likelihood99.68%

FIRST EPSS · score date Jul 26, 2026 · 99.9th percentile · first observed Jul 27, 2026

SeverityCVSS 9.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
vmwareOriginal assertion
Record text

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

Inspect raw assertion
Field
container
Value
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Spring Framework JDK 9+ Remote Code Execution Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Spring Framework JDK 9+ Remote Code Execution Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

99.68% probability · 99.95th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.996770000000; percentile 0.999490000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
98Underlying assertions
39Canonical products
97Target assertions
1Constraint assertions

Grouped from 8 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

40 scope groups

vmware · source assertedn/aSpring FrameworkDirect source scope
Affected: Spring Framework versions 5.3.X prior to 5.3.18+, 5.2.x prior to 5.2.20+ and all old and unsupported versions
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "Spring Framework versions 5.3.X prior to 5.3.18+, 5.2.x prior to 5.2.20+ and all old and unsupported versions"}]
NVD CPE · APPLICATIONciscocx_cloud_agentVulnerable target · 1 assertions
Any version (unconstrained) (< 2.1.0)Canonical identity product-4e8bf7a144087ffa60d1f212b33836542096f22b163f1f72e8a5c06d98dd345aLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:cisco:cx_cloud_agent:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    through excluding 2.1.0
    Match ID
    0da44823-e5f1-4922-bcca-13beb49c017b
NVD CPE · APPLICATIONoraclecommerce_platformVulnerable target · 1 assertions
Version 11.3.2Canonical identity product-e31af4834e1f8a4ea1f7ebe71223981e962f1158336a2dad7b6649aa673b9a38Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:commerce_platform:11.3.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8cde72f7-ed9d-4a53-bf63-df6711ffdef4
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_automated_test_suiteVulnerable target · 2 assertions
Version 1.9.0; Version 22.1.0Canonical identity product-2df9a6c32a69a473630d1002e16384828fb2dfd0bd0fe63d33dbead65a380413Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a4ca84d6-f312-4c29-a02b-050fcb7a902b
  2. cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:22.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2df6c109-e3d3-431c-8101-2ff88763cf5a
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_binding_support_functionVulnerable target · 1 assertions
Version 22.1.3Canonical identity product-8f636e0be037da6bf7c0c258d9b119655a5b5c3ceff4bd38c8b31486a91bdd3aLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.1.3:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6edb6772-7fdb-45ff-8d72-952902a7ee56
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_consoleVulnerable target · 2 assertions
Version 1.9.0; Version 22.1.0Canonical identity product-01043ab8863c950f08a5140b64843c7d6214d4310de5e8b143fadd00a025cdd0Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_cloud_native_core_console:22.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b5bb2213-08e7-497f-b672-556fd682d122
  2. cpe:2.3:a:oracle:communications_cloud_native_core_console:1.9.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    daab7154-4de8-4806-86d0-c1d33b84417b
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_network_exposure_functionVulnerable target · 1 assertions
Version 22.1.0Canonical identity product-ae74202c9cdf761f961de88dab1f78c91dd57134e1263a67eefc984186d67859Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:communications_cloud_native_core_network_exposure_function:22.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e24426ee-6a3f-413e-a70a-fb98ccd007a1
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_network_function_cloud_native_environmentVulnerable target · 2 assertions
Version 1.10.0; Version 22.1.0Canonical identity product-9ce2d2941c587c57bce4542254ac78ecb3a7d200832d68c79ec01a96d6dbd33dLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:1.10.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c2a5b24d-bdf2-423c-98ea-a40778c01a05
  2. cpe:2.3:a:oracle:communications_cloud_native_core_network_function_cloud_native_environment:22.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    04e6c8e9-2024-496c-9bfd-4548a5b44e2e
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_network_repository_functionVulnerable target · 2 assertions
Version 1.15.0; Version 22.1.0Canonical identity product-75c5a7c123633bc487c0b67db5d476ad5d5f58a8838a428cf0d38f32b1071c37Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:22.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b61a7946-f554-44a9-9e41-86114e4b4914
  2. cpe:2.3:a:oracle:communications_cloud_native_core_network_repository_function:1.15.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6f60e32f-0ca0-4c2d-9848-cb92765a9acb
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_network_slice_selection_functionVulnerable target · 3 assertions
Version 1.15.0; Version 1.8.0; Version 22.1.0Canonical identity product-f790488478c9b93947c419cde83308855104b3cb350de53c91c7bbc2ba41d1c2Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.15.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d163aa57-1d66-4fbf-a8bb-f13e56e5c489
  2. cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:22.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d6577f14-36b6-46a5-a1b1-fccada61a23b
  3. cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.8.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3aa09838-bf13-46ac-bb97-a69f48b73a8a
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_policyVulnerable target · 2 assertions
Version 1.15.0; Version 22.1.0Canonical identity product-4906a179e2e22d81b3662b3c3400d77ff228001efb0bd2788c20df60ade3ecf4Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b4367d9b-bf81-47ad-a840-ac46317c774d
  2. cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0425918a-03f1-4541-bdef-55b03e07e115
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_security_edge_protection_proxyVulnerable target · 2 assertions
Version 1.7.0; Version 22.1.0Canonical identity product-fccce0827ed00a3fd1d24f8035017717d00054f35b043380f991f1f4ed03e869Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:22.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d235b299-9a0e-44ff-84f1-2ffbc070a21d
  2. cpe:2.3:a:oracle:communications_cloud_native_core_security_edge_protection_proxy:1.7.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bd4349fe-eef8-489a-8abf-5fcd55ec6de0
NVD CPE · APPLICATIONoraclecommunications_cloud_native_core_unified_data_repositoryVulnerable target · 2 assertions
Version 1.15.0; Version 22.1.0Canonical identity product-1abb2b31f7a04dc2ab0018e61daadf757aa59f886a72f5ee129978998b2a8b0aLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:1.15.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    c6eaa723-2a23-4151-930b-86acf9cc1c0c
  2. cpe:2.3:a:oracle:communications_cloud_native_core_unified_data_repository:22.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 17
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3c2e50b0-64b6-4696-9213-f5d9016058a5
NVD CPE · APPLICATIONoraclecommunications_policy_managementVulnerable target · 1 assertions
Version 12.6.0.0.0Canonical identity product-d355b11887e16a673439034955f56c1713687fe0ddcca9e46745eb07d77aae8bLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:communications_policy_management:12.6.0.0.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 18
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    02aedb9f-1040-4840-acb6-8bf299886acb
NVD CPE · APPLICATIONoraclecommunications_unified_inventory_managementVulnerable target · 3 assertions
Version 7.4.1; Version 7.4.2; Version 7.5.0Canonical identity product-7c46aad31fff3a518404ae5e4975d355e472ccec48579eb65a862ee12e43bd7eLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:communications_unified_inventory_management:7.5.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0ebc7eb1-fd72-4bfc-92cc-7c8b8e462d7c
  2. cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a7637f8b-15f1-42e2-be18-e1ff7c66587d
  3. cpe:2.3:a:oracle:communications_unified_inventory_management:7.4.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e43d793a-7756-4d58-a8ed-72dc4ec9cea7
NVD CPE · APPLICATIONoraclefinancial_services_analytical_applications_infrastructureVulnerable target · 2 assertions
Version 8.1.1; Version 8.1.2.0Canonical identity product-ba2f6e9f72c1209c147c5ead6bbf71a825fad4347275bbe719bc9a5db936c36cLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    41c2c67b-bf55-4b48-a94d-1f37a4fac68c
  2. cpe:2.3:a:oracle:financial_services_analytical_applications_infrastructure:8.1.2.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    172bece8-9626-4910-aaa1-a2fa9c7139e3
NVD CPE · APPLICATIONoraclefinancial_services_behavior_detection_platformVulnerable target · 3 assertions
Version 8.1.1.0; Version 8.1.1.1; Version 8.1.2.0Canonical identity product-58945c34e5ed1dcdf92cae88d718b4d617dea2549ec05647c1621b929370ffbeLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 21
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a4b3a10e-70a8-4332-8567-06ae2c45d3c6
  2. cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.2.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 23
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6cac78ad-86bb-4f06-b8cf-8e1329987f2f
  3. cpe:2.3:a:oracle:financial_services_behavior_detection_platform:8.1.1.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 22
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    059f0d4e-b007-4986-ab95-89f11147cb2b
NVD CPE · APPLICATIONoraclefinancial_services_enterprise_case_managementVulnerable target · 3 assertions
Version 8.1.1.0; Version 8.1.1.1; Version 8.1.2.0Canonical identity product-de3dd2ee460e007361972dc229e47ae95bf4558fd9a5594075335ea80cfe25f0Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.1.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 25
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    fca5dc3f-e7d8-45e3-8114-2213ec631cdf
  2. cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.2.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 26
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    078aefc0-96da-4f50-be8e-8360718103a5
  3. cpe:2.3:a:oracle:financial_services_enterprise_case_management:8.1.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 24
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    44563108-ad89-49a0-9fa5-7de5a5601d2c
NVD CPE · APPLICATIONoraclejdkEnvironmental constraint · 1 assertions
Any version (unconstrained) (>= 9)Canonical identity product-6c94a14e5689a64227066e3f60eeb2b8b30045bcbf08047234f29f3fdd35d120Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:a:oracle:jdk:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    from including 9
    Match ID
    19f22333-401b-4db1-a63d-622fa54c2ba9
NVD CPE · APPLICATIONoraclemysql_enterprise_monitorVulnerable target · 1 assertions
Any version (unconstrained) (< 8.0.29)Canonical identity product-57d551f18f44e8d3873b139bff1d5a2db2f13c717b3d0295e687bd95ab213facLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 27
    Logic
    OR
    Version bounds
    through excluding 8.0.29
    Match ID
    7eccd8c1-c055-4958-a613-b6d1609687f1
NVD CPE · APPLICATIONoracleproduct_lifecycle_analyticsVulnerable target · 1 assertions
Version 3.6.1Canonical identity product-96140747cd8caa2367bbc11701cfd3a965a31bf6eaecb69bda4a18768dbfda10Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:product_lifecycle_analytics:3.6.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 28
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7f978162-cb2c-4166-947a-9048c6e878bc
NVD CPE · APPLICATIONoracleretail_bulk_data_integrationVulnerable target · 1 assertions
Version 16.0.3Canonical identity product-bbdc66f5266de41b9320e69f25ba7d4366dc2012e835207fb21313cb0ba78983Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:oracle:retail_bulk_data_integration:16.0.3:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    3486c85c-57bc-433f-941c-e81539da5c1d
NVD CPE · APPLICATIONoracleretail_customer_management_and_segmentation_foundationVulnerable target · 3 assertions
Version 17.0; Version 18.0; Version 19.0Canonical identity product-42d4fe2707bfb0d8e7968a2730a7ef8c8ef90ec520f2ecab1c3ee2cc5ca1eeb1Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:17.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a7fbf5c7-ec73-4ce4-8cb7-e9cf5705db25
  2. cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:19.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9efaea84-e376-40a2-8c9f-3e0676fec527
  3. cpe:2.3:a:oracle:retail_customer_management_and_segmentation_foundation:18.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    36e16aef-aceb-413c-888c-8d250f65c180
NVD CPE · APPLICATIONoracleretail_financial_integrationVulnerable target · 4 assertions
Version 14.1.3.2; Version 15.0.3.1; Version 16.0.3; Version 19.0.1Canonical identity product-6185dc0f13c23fd1f3aab5817a3544d38e8a1723ff90d57933c579e0121a39f2Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:retail_financial_integration:16.0.3:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6b042849-7ef5-4a5f-b6cd-712c0b8735bf
  2. cpe:2.3:a:oracle:retail_financial_integration:15.0.3.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cb86f6c3-981e-4eca-a5eb-9a9cd73d70c9
  3. cpe:2.3:a:oracle:retail_financial_integration:19.0.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7435071d-0c95-4686-a978-afc4c9a0d0fe
  4. cpe:2.3:a:oracle:retail_financial_integration:14.1.3.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    798e4fee-9b2b-436e-a2b3-b8aa1079892a
NVD CPE · APPLICATIONoracleretail_integration_busVulnerable target · 4 assertions
Version 14.1.3.2; Version 15.0.3.1; Version 16.0.3; Version 19.0.1Canonical identity product-54671a47076b3b659147e04543026968a99e9f513e4236b015793d98b3c0ad16Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:oracle:retail_integration_bus:15.0.3.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a1194c4e-cf42-4b4d-ba9a-40fdd28f1d58
  2. cpe:2.3:a:oracle:retail_integration_bus:16.0.3:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 15
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    822a3c37-86f2-4e91-be91-2a859f983941
  3. cpe:2.3:a:oracle:retail_integration_bus:19.0.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    bd311c33-a309-44d5-bbfb-539d72c7f8c4
  4. cpe:2.3:a:oracle:retail_integration_bus:14.1.3.2:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8cfce558-9972-46a2-8539-c16044f1baa9

Affected-product evidence

Accepted scope and product mapping

38 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-01043ab8863c950f08a5140b64843c7d6214d4310de5e8b143fadd00a025cdd0

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
19ad2d25-0281-49a0-ad00-73961bf65a7f32f9a88f-aa0b-4606-94b6-82641425a3f2
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-0589ffcfca4df227f5832ed31df6cf887bfbdf19ed59a053283476bf563f2f2b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
768ff864-18f4-4f8a-af27-c272fb2f2472
Mapping establishedEvidence supported

vendor-6b310233dbc1eceadb11ae200191b71c5a499cd0c4916b064b08d7f851b21f9f · product-05d76c2c84fdbdeeecc94873e57587b18f42b3dc68851ca136bef620e91b0077

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7da5e678-c26e-4448-8718-ac87ef7b163fc742a187-b12e-4916-98cd-d410940e93ab
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-1abb2b31f7a04dc2ab0018e61daadf757aa59f886a72f5ee129978998b2a8b0a

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0f556f14-2d82-44db-8aa5-be4c4f782d1442d2cc6c-515f-48d8-b9de-070441033eb1
Mapping establishedEvidence supported

vendor-6954abb4893409d403d1a1ecd2c9cf7afa7b121aa149878a168c036f9744efa2 · product-295a5779c54e559abffa59812c596ab8bf3666894fcc388390ef200e9e4e77c7

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3db6a9b8-c768-4f25-9dee-7b49e9a1c40196af18fc-71da-4ed6-9935-84aa6f817947
Mapping establishedEvidence supported

vendor-6954abb4893409d403d1a1ecd2c9cf7afa7b121aa149878a168c036f9744efa2 · product-2abf121d45c91c33241c3b2e9f9fab98d04600551dedbad591e25364a6584042

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1c7347da-0f0e-46b1-b771-84be7718718234db1b03-3315-42da-833f-8aa623305e9f698bdc92-93ae-425f-a3fb-e8f24d5463ad9d1e6a97-4251-4675-92da-05ac1a6790ef9f5f4b83-2d85-45e6-8f45-8a92a162f53a
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-2df9a6c32a69a473630d1002e16384828fb2dfd0bd0fe63d33dbead65a380413

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
215f3e31-4aa3-4084-88a4-08f0b13ec72559fbca05-c491-4768-8e48-14781cf3884f
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-4074453fd17dd84726e7e2722aaa2ca5f508fb2322949df8628cbd14058e75aa

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5902c32e-073f-4056-940e-3c9c8b0ba7ca913edaaa-f45a-4b63-9b4f-72c2f12dfa3e
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-42d4fe2707bfb0d8e7968a2730a7ef8c8ef90ec520f2ecab1c3ee2cc5ca1eeb1

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
24d5db4f-9b6a-4fa1-8333-f43e5c58f8c93b11b157-19db-461c-923e-ee3d81b0a64b67efcfe7-9c24-4a63-81a7-5c53a059b8ff
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-4906a179e2e22d81b3662b3c3400d77ff228001efb0bd2788c20df60ade3ecf4

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
494d9981-13a5-46e3-b2d8-8b8ece8c98ebb9b13c9e-359d-4b16-8c59-20368dcea102
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-4959ee4bbf108a9dd17d3c6401b677b23565e55bd178aa90c0f8f9751773defb

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2f302df2-8341-420d-a024-36608215e6e34fcb65c0-0918-4664-aec1-b2cd857b08fa70e3693d-3902-424f-8002-6ef49d7f4605d9566ac2-377a-40b0-b40f-9ee6acd3d57c
Mapping establishedEvidence supported

vendor-6954abb4893409d403d1a1ecd2c9cf7afa7b121aa149878a168c036f9744efa2 · product-4dea60c925597c0121373719449472a92bf1213a622b5b6e84f0a2fa860287ba

Source class
Nvd cpe vulnerable target
Assertions
7
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0f461be5-1ad1-4adf-afdc-6c753687ceaf384cc804-5f87-458b-b563-9202bab44bbc3d31bd43-d350-4d9e-8020-4912a71b977e52c91b45-381f-4797-ba06-dfa66c9e481c5f05d0f4-80a0-412f-96fc-1cdd2275bcd95f2713f5-cc27-4c9a-81f8-cf71d61b27e2e3f0e748-5751-41d9-8ed1-143e06f40352
Mapping establishedEvidence supported

vendor-0774b265c0e837e737aaf99ed0f2450c048e61f34267ca59d8623878b839334e · product-4e8bf7a144087ffa60d1f212b33836542096f22b163f1f72e8a5c06d98dd345a

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
42b274f6-4f3b-4d48-ba61-3fa5a16c6f41
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-54671a47076b3b659147e04543026968a99e9f513e4236b015793d98b3c0ad16

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1f9e4d33-0e69-4e9b-94e9-7a19a5f55e997eac61e7-8e40-4fa0-b880-56c374bc2495a495c5e6-3959-4662-bf73-5e761b564abea9a5ecf2-b767-43e8-a48d-3eb810f784e2
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-57d551f18f44e8d3873b139bff1d5a2db2f13c717b3d0295e687bd95ab213fac

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
28934bd6-0f5e-4538-af10-c6b91048e467
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-58945c34e5ed1dcdf92cae88d718b4d617dea2549ec05647c1621b929370ffbe

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1ca43889-585d-433f-88c6-7151340b877e2899303b-7252-4071-b0d6-a524ba6c7189a4173412-5091-4138-8939-4b00f8bd3ba3
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-6185dc0f13c23fd1f3aab5817a3544d38e8a1723ff90d57933c579e0121a39f2

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
08055ac3-eebd-4d5b-a21e-e1ccb6ba85962a4da79a-d52d-489f-88c3-f64abe51a7ec554800a2-21f4-40b4-8396-e7241cede86bc0cb0830-6b24-4ea9-93cf-ca6be8de44eb
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-7408bee14b201df56ba79a093a16ebcccdd09751b1d73782c2ea9e3f85eee87e

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
188139ba-ae3e-48e6-8da1-56f6ede92a22f9b26f5e-1d2c-417e-91a9-9bf4ca483a67fdc65ef7-c8ef-4ddc-be69-e0a31f4374a7
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-75c5a7c123633bc487c0b67db5d476ad5d5f58a8838a428cf0d38f32b1071c37

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
57893c3c-903f-4a41-80cc-64c40baa4b6dd9c3d813-9f52-4b2e-84cf-15ebaf6962e9
Mapping establishedEvidence supported

vendor-6954abb4893409d403d1a1ecd2c9cf7afa7b121aa149878a168c036f9744efa2 · product-7b0b49a3ec0520c832e70b32f47d499bacb57d31cf1b56cc0d511b89a1df7de5

Source class
Nvd cpe vulnerable target
Assertions
7
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0c697060-47f4-4106-b84c-3f3c6bed5a3f38b494f4-f7de-47cd-9cea-396a75417a4254316309-e7e5-47cc-85be-9604851a19579a1266bd-d459-4084-9303-f0563aba7381a9538596-169d-436b-b41a-0fd064d6c53fbcc3a4f6-9da1-49aa-bf18-cc4db58bb3b8d9051df3-8cc5-4184-8024-607e5f201e52
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-7c46aad31fff3a518404ae5e4975d355e472ccec48579eb65a862ee12e43bd7e

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0f7f10f1-85a1-45eb-8476-16258f7bb2ed5f6a0b3b-2ce4-4dc6-8f62-fba6b71de20c6fe5d233-9cdf-45d7-a43a-2e72c28c2ade
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-8f636e0be037da6bf7c0c258d9b119655a5b5c3ceff4bd38c8b31486a91bdd3a

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
a28093c4-81f0-4135-bf84-b7827a8b1267
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-8fa3b79bf349a1d0accbbc5b10cb0a9b023a8753710e655ec6ac2d3940b634e9

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0a7bce5a-d80f-4a87-a44e-1783c05c977f987e5f88-f40a-4169-9e0a-c80ca4e0c607
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-96140747cd8caa2367bbc11701cfd3a965a31bf6eaecb69bda4a18768dbfda10

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
05190080-965e-4838-8191-f1f1783a3a68
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-9ce2d2941c587c57bce4542254ac78ecb3a7d200832d68c79ec01a96d6dbd33d

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
6b28089f-ee4a-45fd-b495-5d68bf2bee38d3397274-a6dc-4e49-b511-cef453675117
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-ae74202c9cdf761f961de88dab1f78c91dd57134e1263a67eefc984186d67859

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
cbec4e82-0e38-45f9-905c-2189df907468
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-ba2f6e9f72c1209c147c5ead6bbf71a825fad4347275bbe719bc9a5db936c36c

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0a252466-af88-4c7f-a1db-c7785822d995523b9125-0b91-44a8-ba5a-84b071577dab
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-bbdc66f5266de41b9320e69f25ba7d4366dc2012e835207fb21313cb0ba78983

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
8bbfb35b-d694-402a-b8e6-91b6d93bbc33
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-c04567699fe15f01ca354326b240a6ee6547e2c9ce5ee394b481a5e585d56900

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
44be1464-14f2-46e2-943e-223632477fe7a1db46d3-1563-498c-b069-e257ce4067f9
Mapping establishedEvidence supported

vendor-6954abb4893409d403d1a1ecd2c9cf7afa7b121aa149878a168c036f9744efa2 · product-c6fb68e09db6c0f9010034cf2e69c04f697b089e4ebfbddb2b20d260a2589352

Source class
Nvd cpe vulnerable target
Assertions
6
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
69719a00-150c-486e-9c79-ff52da1141de76fe926a-0ae0-4eae-81ff-c0c1b70e4fe481ff99c9-696f-40c3-bcdf-f03c8a120423847beae8-3dc7-4812-83e8-771fa94badde9f45f8f0-1ce1-4c4f-916a-57e78eae17f1f34edad7-8aee-4076-8af2-810ba924be51
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-d355b11887e16a673439034955f56c1713687fe0ddcca9e46745eb07d77aae8b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
a3851070-854a-4a2b-b6e2-da8909eaf97d
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-de3dd2ee460e007361972dc229e47ae95bf4558fd9a5594075335ea80cfe25f0

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2e282c2f-3116-4666-b1af-2698133c9d3344603af8-5adf-4326-aff8-c07971b0f4b7e459674d-98fa-4062-9f29-861a2decc500
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-e31af4834e1f8a4ea1f7ebe71223981e962f1158336a2dad7b6649aa673b9a38

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7daa2ee9-cd16-4882-b96c-9b95dd2bb549
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-e8d03681a172c72694a666049fe3288ab1bd0272ee81de5fe266611ef2670b1c

Source class
Nvd cpe vulnerable target
Assertions
4
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
24515114-3556-4fbf-b6ef-6067a6cb7d0b3674670b-e207-44fb-b513-e51e33ffcf967d665ff4-4d33-4f7d-b042-debbd55fc7dffa4e42d0-46fb-4f0e-8cbc-8ff045b897b5
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-f790488478c9b93947c419cde83308855104b3cb350de53c91c7bbc2ba41d1c2

Source class
Nvd cpe vulnerable target
Assertions
3
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3749df59-f241-4d06-a481-f419224369577c7c0fd0-4528-4558-bce0-904e264f5b8ba2b9caae-c363-43a4-91c9-db251cce552f
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-fccce0827ed00a3fd1d24f8035017717d00054f35b043380f991f1f4ed03e869

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
b38df0e1-b97c-4d95-9af3-e66e324bcd94b3e14077-7c0d-4bcb-ab0e-0382e9d90570
Mapping establishedEvidence supported

vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-fe54a3411cb03c65b861b267a632e209a8aa64f29e4be16a74e160ab49948cbc

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c35a4c04-37e3-46a0-8d35-3b0524edc7a6
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-feb415d823d08ef5e15c1ca08b2509755fcec090029cabc0ca257ffebea36af9

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
9d092737-d552-44e2-957a-acda0f40b3909f80138a-7d6f-4fec-a51d-b2377f507729
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
1400c2d9-3e3c-4f3f-b99b-4244633f9261

Assessments

CVSS by origin

9.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
7.5
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:N/AC:L/Au:N/C:P/I:P/A:P
9.8
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
9.8
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

9.8Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Validation
Valid match
Recomputed
9.8
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.