Y4er
22 exploits
Active since Jan 2020
Oracle Access Manager unauthenticated Remote Code Execution
Oracle WebLogic Server <12.2.1.4 - RCE
Oracle Access Manager unauthenticated Remote Code Execution
Oracle Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3-4 - RCE
Oracle WebLogic Server <12.2.1.4 - RCE
ForgeRock Access Management < 6.5.4 & OpenAM 9.0.0-14.6.3 - RCE via Jato PageSession Deserialization
Oracle Coherence <=14.1.1.0.0 - Unauthenticated Remote Code Execution via IIOP/T3
Oracle WebLogic Server <14.1.1.0.0 - RCE
SolarWinds Orion Platform < 2020.2.5 - Authenticated Remote Code Execution via Insecure Deserialization
Oracle WebLogic Server 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0, 14.1.1.0.0 - Unauthenticated Partial Denial of Service via T3
Oracle WebLogic Server <14.1.1.0.0 - RCE
CVSS 9.8
Oracle Access Manager unauthenticated Remote Code Execution
CVSS 9.8
Oracle Access Manager unauthenticated Remote Code Execution
CVSS 9.8
Oracle Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3-4 - RCE
CVSS 9.8
Oracle Fusion Middleware - OpenSSO Agent - Unauthenticated RCE
CVSS 9.8
Bitbucket Server/Data Center - Command Injection
CVSS 9.8
Oracle Access Manager unauthenticated Remote Code Execution
CVSS 9.8
Oracle Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3-4 - RCE
CVSS 9.8
Product <Version> - Command Injection
CVSS 9.8
ManageEngine ServiceDesk Plus CVE-2021-44077
CVSS 9.8
ManageEngine Password Manager Pro <12101 & PAM360 <5510 - RCE via Java Deserialization
CVSS 9.8
Oracle Coherence 3.7.1.0/12.1.3.0.0/12.2.1.3-4 - RCE
CVSS 9.8