[Git][security-tracker-team/security-tracker][master] auto-nfu: Extend Oracle rule

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Aug 19 10:12:14 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
cb90a6eb by Moritz Muehlenhoff at 2026-08-19T11:07:05+02:00
auto-nfu: Extend Oracle rule

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -339,7 +339,7 @@ CVE-2026-71114 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virt
 CVE-2026-71113 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
 	- virtualbox <unfixed>
 CVE-2026-71112 (Vulnerability in the PeopleSoft Enterprise FIN Common Objects product  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71111 (Vulnerability in the Oracle Identity Manager product of Oracle Fusion  ...)
 	NOT-FOR-US: Oracle
 CVE-2026-71110 (Vulnerability in the Helidon product of Oracle Fusion Middleware (comp ...)
@@ -355,13 +355,13 @@ CVE-2026-71106 (Vulnerability in the Oracle Hospitality OPERA 5 Property Service
 CVE-2026-71105 (Vulnerability in the Oracle Hyperion Financial Management product of O ...)
 	NOT-FOR-US: Oracle
 CVE-2026-71104 (Vulnerability in the Oracle HRMS (Netherlands) product of Oracle E-Bus ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71103 (Vulnerability in the Oracle Hyperion Financial Management product of O ...)
 	NOT-FOR-US: Oracle
 CVE-2026-71102 (Vulnerability in the Portable Clusterware component of Oracle Database ...)
 	NOT-FOR-US: Oracle
 CVE-2026-71101 (Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Sui ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71100 (Vulnerability in the RDBMS component of Oracle Database Server.  Suppo ...)
 	NOT-FOR-US: Oracle
 CVE-2026-71099 (Vulnerability in the Oracle Business Intelligence Enterprise Edition p ...)
@@ -383,51 +383,51 @@ CVE-2026-71091 (Vulnerability in the Oracle Hyperion Financial Management produc
 CVE-2026-71090 (Vulnerability in the Oracle Hyperion Financial Management product of O ...)
 	NOT-FOR-US: Oracle
 CVE-2026-71089 (Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71088 (Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71087 (Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71085 (Vulnerability in the Oracle Hyperion Financial Management product of O ...)
 	NOT-FOR-US: Oracle
 CVE-2026-71084 (Vulnerability in the MySQL Connectors product of Oracle MySQL (compone ...)
 	TODO: check
 CVE-2026-71083 (Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71082 (Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71081 (Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71080 (Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71079 (Vulnerability in the MySQL Connectors product of Oracle MySQL (compone ...)
 	TODO: check
 CVE-2026-71078 (Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71077 (Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71076 (Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71075 (Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71074 (Vulnerability in the Helidon product of Oracle Fusion Middleware (comp ...)
 	NOT-FOR-US: Oracle
 CVE-2026-71073 (Vulnerability in the MySQL Connectors product of Oracle MySQL (compone ...)
 	TODO: check
 CVE-2026-71072 (Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71071 (Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71070 (Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71069 (Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71068 (Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71067 (Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71066 (Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71065 (Vulnerability in the Helidon product of Oracle Fusion Middleware (comp ...)
 	NOT-FOR-US: Oracle
 CVE-2026-71064 (Vulnerability in the Portable Clusterware component of Oracle Database ...)
@@ -451,17 +451,17 @@ CVE-2026-71056 (Vulnerability in the Oracle Business Intelligence Enterprise Edi
 CVE-2026-71055 (Vulnerability in the Oracle Business Intelligence Enterprise Edition p ...)
 	NOT-FOR-US: Oracle
 CVE-2026-71053 (Vulnerability in the Oracle Agile Engineering Data Management product  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71052 (Vulnerability in the Oracle Agile Engineering Data Management product  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71051 (Vulnerability in the Oracle Product Lifecycle Analytics product of Ora ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71050 (Vulnerability in the Oracle Product Lifecycle Analytics product of Ora ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71049 (Vulnerability in the Oracle Product Lifecycle Analytics product of Ora ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71048 (Vulnerability in the Oracle Product Lifecycle Analytics product of Ora ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-71046 (Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain ( ...)
 	NOT-FOR-US: Oracle
 CVE-2026-71045 (Vulnerability in the Oracle Agile PLM product of Oracle Supply Chain ( ...)
@@ -1111,13 +1111,13 @@ CVE-2026-70714 (Vulnerability in the Oracle Hyperion Calculation Manager product
 CVE-2026-70713 (Vulnerability in the Oracle iSetup product of Oracle E-Business Suite  ...)
 	NOT-FOR-US: Oracle
 CVE-2026-70712 (Vulnerability in the Oracle Agile Engineering Data Management product  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-70711 (Vulnerability in the Oracle Hyperion Calculation Manager product of Or ...)
 	TODO: check
 CVE-2026-70710 (Vulnerability in the Oracle Sales Foundation product of Oracle E-Busin ...)
 	TODO: check
 CVE-2026-70709 (Vulnerability in the Oracle Agile Engineering Data Management product  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-70708 (Vulnerability in the Oracle Sales Foundation product of Oracle E-Busin ...)
 	TODO: check
 CVE-2026-70707 (Vulnerability in the Oracle Sales for Handhelds product of Oracle E-Bu ...)
@@ -1129,7 +1129,7 @@ CVE-2026-70705 (Vulnerability in the Oracle Hyperion Calculation Manager product
 CVE-2026-70704 (Vulnerability in the Oracle Trading Community product of Oracle E-Busi ...)
 	TODO: check
 CVE-2026-70703 (Vulnerability in the Oracle Agile Engineering Data Management product  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-70702 (Vulnerability in the Oracle Payments product of Oracle E-Business Suit ...)
 	TODO: check
 CVE-2026-70701 (Vulnerability in the Oracle Payables product of Oracle E-Business Suit ...)
@@ -1139,9 +1139,9 @@ CVE-2026-70700 (Vulnerability in the Oracle Payables product of Oracle E-Busines
 CVE-2026-70699 (Vulnerability in the Oracle Payments product of Oracle E-Business Suit ...)
 	TODO: check
 CVE-2026-70698 (Vulnerability in the Oracle Agile Engineering Data Management product  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-70697 (Vulnerability in the Oracle Agile Engineering Data Management product  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-70696 (Vulnerability in the Oracle Payments product of Oracle E-Business Suit ...)
 	TODO: check
 CVE-2026-70695 (Vulnerability in the Oracle Payments product of Oracle E-Business Suit ...)
@@ -1149,13 +1149,13 @@ CVE-2026-70695 (Vulnerability in the Oracle Payments product of Oracle E-Busines
 CVE-2026-70694 (Vulnerability in the Oracle Payments product of Oracle E-Business Suit ...)
 	TODO: check
 CVE-2026-70693 (Vulnerability in the Oracle Agile Engineering Data Management product  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-70692 (Vulnerability in the Oracle Marketing Encyclopedia System product of O ...)
 	TODO: check
 CVE-2026-70691 (Vulnerability in the Oracle Agile Engineering Data Management product  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-70690 (Vulnerability in the Oracle HRMS (US) product of Oracle E-Business Sui ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-70689 (Vulnerability in Oracle Essbase (component: Infrastructure).   The sup ...)
 	NOT-FOR-US: Oracle
 CVE-2026-70688 (Vulnerability in Oracle Essbase (component: Calculator).   The support ...)


=====================================
data/packages/nfu.yaml
=====================================
@@ -649,7 +649,9 @@
       - product: Oracle Access Manager
       - product: Oracle Advanced Inbound Telephony
       - product: Oracle Advanced Outbound Telephony
+      - product: Oracle Agile Engineering Data Management
       - product: Oracle Agile PLM
+      - product: Oracle Agile PLM MCAD Connector
       - product: Oracle Agile Product Lifecycle Management for Process
       - product: Oracle Application Development Framework (ADF)
       - product: Oracle Application Express
@@ -689,7 +691,9 @@
       - product: Oracle GoldenGate
       - product: Oracle HCM Common Architecture
       - product: Oracle Health Sciences Data Management Workbench
+      - product: Oracle HRMS (Netherlands)
       - product: Oracle HRMS (UK)
+      - product: Oracle HRMS (US)
       - product: Oracle Hospitality OPERA 5
       - product: Oracle Hospitality OPERA 5 Property Services
       - product: Oracle Hospitality Simphony
@@ -718,6 +722,7 @@
       - product: Oracle Process Manufacturing Product Development
       - product: Oracle Process Manufacturing Process Planning
       - product: Oracle Product Hub
+      - product: Oracle Product Lifecycle Analytics
       - product: Oracle Project Portfolio Analysis
       - product: Oracle Property Manager
       - product: Oracle Public Sector Financials (International)
@@ -752,6 +757,7 @@
       - product: PeopleSoft Enterprise CS Campus Community
       - product: PeopleSoft Enterprise CS Student Financials
       - product: PeopleSoft Enterprise CS Student Records
+      - product: PeopleSoft Enterprise FIN Common Objects
       - product: PeopleSoft Enterprise FIN Contracts
       - product: PeopleSoft Enterprise FIN IT Asset Management
       - product: PeopleSoft Enterprise FIN Maintenance Management



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb90a6ebbc79d3c7c6105ccf9f46ad1b2df70e22

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb90a6ebbc79d3c7c6105ccf9f46ad1b2df70e22
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/b6adfa37/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list