[Git][security-tracker-team/security-tracker][master] Process various Oracle related CVEs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 18 21:01:11 BST 2024



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3712ff60 by Salvatore Bonaccorso at 2024-07-18T22:00:21+02:00
Process various Oracle related CVEs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -255,129 +255,129 @@ CVE-2024-21687 (This High severity File Inclusion vulnerability was introduced i
 CVE-2024-21188 (Vulnerability in the Oracle Financial Services Revenue Management and  ...)
 	NOT-FOR-US: Oracle
 CVE-2024-21185 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 <unfixed>
 CVE-2024-21184 (Vulnerability in the Oracle Database RDBMS Security component of Oracl ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21183 (Vulnerability in the Oracle WebLogic Server product of Oracle Fusion M ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21182 (Vulnerability in the Oracle WebLogic Server product of Oracle Fusion M ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21181 (Vulnerability in the Oracle WebLogic Server product of Oracle Fusion M ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21180 (Vulnerability in the PeopleSoft Enterprise PeopleTools product of Orac ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21179 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.38-1
 CVE-2024-21178 (Vulnerability in the PeopleSoft Enterprise PeopleTools product of Orac ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21177 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.38-1
 CVE-2024-21176 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 <not-affected> (Vulnerable code not present)
 CVE-2024-21175 (Vulnerability in the Oracle WebLogic Server product of Oracle Fusion M ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21174 (Vulnerability in the Java VM component of Oracle Database Server.  Sup ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21173 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.38-1
 CVE-2024-21171 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.38-1
 CVE-2024-21170 (Vulnerability in the MySQL Connectors product of Oracle MySQL (compone ...)
-	TODO: check
+	- mysql-connector-python <unfixed>
 CVE-2024-21169 (Vulnerability in the Oracle Marketing product of Oracle E-Business Sui ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21168 (Vulnerability in the JD Edwards EnterpriseOne Orchestrator product of  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21167 (Vulnerability in the Oracle Trading Community product of Oracle E-Busi ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21166 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.37-1
 CVE-2024-21165 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.38-1
 CVE-2024-21164 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
-	TODO: check
+	- virtualbox 7.0.20-dfsg-1
 CVE-2024-21163 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.38-1
 CVE-2024-21162 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.38-1
 CVE-2024-21161 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
-	TODO: check
+	- virtualbox 7.0.20-dfsg-1
 CVE-2024-21160 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.37-1
 CVE-2024-21159 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.37-1
 CVE-2024-21158 (Vulnerability in the PeopleSoft Enterprise PeopleTools product of Orac ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21157 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.37-1
 CVE-2024-21155 (Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracl ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21154 (Vulnerability in the PeopleSoft Enterprise HCM Human Resources product ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21153 (Vulnerability in the Oracle Process Manufacturing Product Development  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21152 (Vulnerability in the Oracle Process Manufacturing Financials product o ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21151 (Vulnerability in the Oracle Solaris product of Oracle Systems (compone ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21150 (Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21149 (Vulnerability in the Oracle Enterprise Asset Management product of Ora ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21148 (Vulnerability in the Oracle Applications Framework product of Oracle E ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21147 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
 	TODO: check
 CVE-2024-21146 (Vulnerability in the Oracle Trade Management product of Oracle E-Busin ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21145 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
 	TODO: check
 CVE-2024-21144 (Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition ...)
 	TODO: check
 CVE-2024-21143 (Vulnerability in the Oracle iStore product of Oracle E-Business Suite  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21142 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.38-1
 CVE-2024-21141 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
-	TODO: check
+	- virtualbox 7.0.20-dfsg-1
 CVE-2024-21140 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
 	TODO: check
 CVE-2024-21139 (Vulnerability in the Oracle Business Intelligence Enterprise Edition p ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21138 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
 	TODO: check
 CVE-2024-21137 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.36-1
 CVE-2024-21136 (Vulnerability in the Oracle Retail Xstore Office product of Oracle Ret ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21135 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.37-1
 CVE-2024-21134 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.38-1
 CVE-2024-21133 (Vulnerability in the Oracle Reports Developer product of Oracle Fusion ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21132 (Vulnerability in the Oracle Purchasing product of Oracle E-Business Su ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21131 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
 	TODO: check
 CVE-2024-21130 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.38-1
 CVE-2024-21129 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.38-1
 CVE-2024-21128 (Vulnerability in the Oracle Application Object Library product of Orac ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21127 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.38-1
 CVE-2024-21126 (Vulnerability in the Oracle Database Portable Clusterware component of ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21125 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.38-1
 CVE-2024-21123 (Vulnerability in the Oracle Database Core component of Oracle Database ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-21122 (Vulnerability in the PeopleSoft Enterprise HCM Shared Components produ ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2024-20996 (Vulnerability in the MySQL Server product of Oracle MySQL (component:  ...)
-	TODO: check
+	- mysql-8.0 8.0.38-1
 CVE-2023-7013 (Inappropriate implementation in Compositing in Google Chrome prior to  ...)
 	TODO: check
 CVE-2023-7012 (Insufficient data validation in Permission Prompts in Google Chrome pr ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3712ff6040b9661a2607ed3cae1fb033ed0df714

-- 
This project does not include diff previews in email notifications.
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3712ff6040b9661a2607ed3cae1fb033ed0df714
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20240718/905e661c/attachment.htm>


More information about the debian-security-tracker-commits mailing list