# Sort by Deepinfo Severity

OpenSSL CVEs sorted by Deepinfo severity.

Source: https://docs.deepinfo.com/reference/vulnerability/search/examples/sort-base-severity/

Last updated: 2026-09-26

---
`POST https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25`

OpenSSL CVEs sorted by Deepinfo severity.

Example 7 of 9 in **Sorting** · [Vulnerability Search Examples](/reference/vulnerability/search/examples/) · endpoint: [Search](/reference/vulnerability/search/)

Tags: `field` `enrichment.cpe.vendor` · `field` `enrichment.cpe.product` · `operator` `eq` · `sort` `enrichment.vdeep_metric.cvss_data.base_severity` · `order` `asc`

Sorts by `enrichment.vdeep_metric.cvss_data.base_severity` ascending: the first results are `LOW`.

In the response, look at `results[].enrichment.vdeep_metric.cvss_data.base_severity`.

## Request

| Parameter | In | Value |
|---|---|---|
| `page_size` | query | `25` |
| `filters.must[0].name` | body | `enrichment.cpe.vendor` |
| `filters.must[0].type` | body | `eq` |
| `filters.must[0].value` | body | `openssl` |
| `filters.must[1].name` | body | `enrichment.cpe.product` |
| `filters.must[1].type` | body | `eq` |
| `filters.must[1].value` | body | `openssl` |
| `sort[0].field` | body | `enrichment.vdeep_metric.cvss_data.base_severity` |
| `sort[0].order` | body | `asc` |

```bash
curl -X POST 'https://api.deepinfo.com/v1/discovery/vulnerability-search?page_size=25' \
  -H 'apikey: YOUR_API_KEY' \
  -H 'Accept: application/json' \
  -H 'Content-Type: application/json' \
  -d '{
  "filters": {
    "must": [
      {
        "name": "enrichment.cpe.vendor",
        "type": "eq",
        "value": "openssl"
      },
      {
        "name": "enrichment.cpe.product",
        "type": "eq",
        "value": "openssl"
      }
    ]
  },
  "sort": [
    {
      "field": "enrichment.vdeep_metric.cvss_data.base_severity",
      "order": "asc"
    }
  ]
}'
```

## Response

### 200 · OK

> Shortened for this page: results: 3 of 25 shown; results[].references: first 10 items; results[].configurations[].nodes[].cpe_match: first 10 items; results[].enrichment.cpe: first 10 items

`Content-Type: application/json` · `ratelimit-limit: 1` · `ratelimit-remaining: 0` · `ratelimit-reset: 1` · `x-ratelimit-limit-second: 1` · `x-ratelimit-remaining-second: 0` · `deepinfo-request-id: 5f0c6a8e-1b2d-4c3e-9f4a-7b8c9d0e1f2a`

```json
{
  "page": 1,
  "page_size": 25,
  "result_count": 303,
  "results": [
    {
      "id": "CVE-2026-42770",
      "source_identifier": "user@openssl.org",
      "published": "2026-06-09T17:17:08Z",
      "last_modified": "2026-07-23T08:10:00Z",
      "status": "Modified",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "Issue summary: When EVP_PKEY_derive_set_peer() is called with a DHX (X9.42)\npeer key, the peer key is not properly checked for the subgroup membership.\n\nImpact summary: A malicious peer which presents an X9.42 key carrying the\nvictim's p and g parameters, a forged q = r (a small prime factor of the\ncofactor (p−1)/q_local), and a public value Y of order r can recover the\nvictim's private key after a small number of key exchange attempts.\n\nWhen EVP_PKEY_derive_set_peer() is called with a DHX (X9.42) peer key, the\nsubgroup membership check Y^q ≡ 1 (mod p) is performed using the peer's\nown q parameter, not the local key's q. The peer's domain parameters are\nthen matched against the domain parameters of the private key, but the value\nof q is not compared.\n\nA malicious peer who presents an X9.42 key carrying the victim's p, g,\na forged q = r (a small prime factor of the cofactor), and a public\nvalue Y of order r passes all checks. The shared secret then takes only\nr distinct values, leaking priv mod r. Repeating for each small-prime\nfactor of the cofactor and combining via CRT recovers the full private\nkey (Lim–Lee / small-subgroup-confinement attack).\n\nThe realistic attack surface is narrow: principally CMP deployments with\nlong-lived RA/CA DHX keys and bespoke enterprise or government applications\nusing X9.42 DHX static keys with interactive protocols and therefore this\nissue was assigned Low severity.\n\nThe FIPS modules in 4.0, 3.6, 3.5, 3.4, 3.1.2 and 3.0 are affected by this\nissue."
        },
        {
          "lang": "es",
          "value": "Resumen del problema: Cuando se llama a EVP_PKEY_derive_set_peer() con una clave de par DHX (X9.42), la clave de par no se verifica correctamente para la pertenencia al subgrupo.\n\nResumen del impacto: Un par malicioso que presenta una clave X9.42 que contiene los parámetros p y g de la víctima, una q forjada = r (un pequeño factor primo del cofactor (p?1)/q_local), y un valor público Y de orden r puede recuperar la clave privada de la víctima después de un pequeño número de intentos de intercambio de claves.\n\nCuando se llama a EVP_PKEY_derive_set_peer() con una clave de par DHX (X9.42), la verificación de pertenencia al subgrupo Y^q ? 1 (mod p) se realiza utilizando el propio parámetro q del par, no la q de la clave local. Los parámetros de dominio del par se comparan entonces con los parámetros de dominio de la clave privada, pero el valor de q no se compara.\n\nUn par malicioso que presenta una clave X9.42 que contiene la p, g de la víctima, una q forjada = r (un pequeño factor primo del cofactor), y un valor público Y de orden r pasa todas las verificaciones. El secreto compartido toma entonces solo r valores distintos, filtrando priv mod r. Repitiendo para cada factor primo pequeño del cofactor y combinando mediante CRT se recupera la clave privada completa (ataque Lim-Lee / de confinamiento de subgrupo pequeño).\n\nLa superficie de ataque realista es estrecha: principalmente despliegues de CMP con claves DHX de RA/CA de larga duración y aplicaciones empresariales o gubernamentales a medida que utilizan claves estáticas DHX X9.42 con protocolos interactivos y, por lo tanto, a este problema se le asignó una severidad Baja.\n\nLos módulos FIPS en 4.0, 3.6, 3.5, 3.4 y 3.0 se ven afectados por este problema."
        }
      ],
      "references": [
        {
          "url": "https://github.com/openssl/openssl/commit/3da5a516cd2635a320ff748503db2cef7c4b0f02",
          "source": "user@openssl.org",
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/openssl/openssl/commit/3ddbb7ab50bd93dfc59cbe08e269a67605aeebdb",
          "source": "user@openssl.org",
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/openssl/openssl/commit/5f452bba2c681423d8fcffd120a19b757ee42e3c",
          "source": "user@openssl.org",
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/openssl/openssl/commit/7fbfde7677ed8808828bf00ff01c937ca04bdda2",
          "source": "user@openssl.org",
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/openssl/openssl/commit/ca2237ab5615641b662183b077f62c08d75e8070",
          "source": "user@openssl.org",
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt",
          "source": "user@openssl.org",
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "attack_vector": "NETWORK",
              "attack_complexity": "HIGH",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "UNCHANGED",
              "confidentiality_impact": "LOW",
              "integrity_impact": "NONE",
              "availability_impact": "NONE",
              "base_score": 3.7,
              "base_severity": "LOW",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 2.2,
            "impact_score": 1.4
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "user@openssl.org",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-325"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "EDB88756-EDFE-4886-A267-3F19342A6042",
                  "version_start_including": "3.0.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "3.0.21"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "BF7E21E7-AEC0-4882-B1F1-2D056B506F22",
                  "version_start_including": "3.4.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "3.4.6"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "6B6B9930-C549-4D88-9784-AF32CCDDB87A",
                  "version_start_including": "3.5.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "3.5.7"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "D41B3C45-EC73-4DC8-989D-B2E2792E102F",
                  "version_start_including": "3.6.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "3.6.3"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:*",
                  "match_criteria_id": "6E881B9A-1A0A-4BC0-8160-20C00561167D",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
            "vendor": "openssl",
            "product": "openssl",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "3.0.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "3.0.21",
            "affected_versions_first": "3.0.0",
            "affected_versions_last": "3.0.20"
          },
          {
            "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
            "vendor": "openssl",
            "product": "openssl",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "3.4.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "3.4.6",
            "affected_versions_first": "3.4.0",
            "affected_versions_last": "3.4.5"
          },
          {
            "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
            "vendor": "openssl",
            "product": "openssl",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "3.5.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "3.5.7",
            "affected_versions_first": "3.5.0",
            "affected_versions_last": "3.5.6"
          },
          {
            "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
            "vendor": "openssl",
            "product": "openssl",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "3.6.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "3.6.3",
            "affected_versions_first": "3.6.0",
            "affected_versions_last": "3.6.2"
          },
          {
            "criteria": "cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:*",
            "vendor": "openssl",
            "product": "openssl",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "4.0.0",
            "affected_versions_last": "4.0.0"
          }
        ],
        "cwe": [
          {
            "id": 325,
            "owasptop10_2021": "A02 Cryptographic Failures",
            "name": "Missing Cryptographic Step",
            "description": "The product does not implement a required step in a cryptographic algorithm, resulting in weaker encryption than advertised by the algorithm.",
            "capec_id": [
              68
            ],
            "scope": [
              "Access Control",
              "Accountability",
              "Confidentiality",
              "Integrity",
              "Non-Repudiation"
            ],
            "impact": [
              "Bypass Protection Mechanism",
              "Hide Activities",
              "Modify Application Data",
              "Read Application Data"
            ],
            "detection_method": [
              "Automated Static Analysis"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.00503,
          "percentile": 0.42062,
          "date": "2026-09-23"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "3.1"
          ],
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "attack_vector": "NETWORK",
            "attack_complexity": "HIGH",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "LOW",
            "vulnerable_system_integrity": "NONE",
            "vulnerable_system_availability": "NONE",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 3.7,
            "base_severity": "LOW"
          }
        }
      }
    },
    {
      "id": "CVE-2026-42768",
      "source_identifier": "user@openssl.org",
      "published": "2026-06-09T17:17:08Z",
      "last_modified": "2026-07-23T08:10:00Z",
      "status": "Analyzed",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "Issue summary: The CMS_decrypt and PKCS7_decrypt functions are vulnerable to\nBleichenbacher-style attack when an attacker is able to provide the CMS or\nS/MIME messages and observe the error code and/or decryption output.\n\nImpact summary: The Bleichenbacher-style attack allows an attacker to use the\nvictim's vulnerable application as a way to decrypt or sign messages with the\nvictim's private RSA key.\n\nThe attack is possible in 2 variants.\n\n1. The decryption API (CMS_decrypt(), PKCS7_decrypt()) is used without\nproviding the recipient certificate. In this case OpenSSL iterates over every\nKeyTransRecipientInfo (KTRI) without stopping at the first success.\n\nAn attacker who authors a message with two KTRI entries — the first one\nwrapping a real CEK under the victim's public key, the second with an\narbitrary probe ciphertext — obtains opportunity to iterate the 2nd KTRI to\nget a valid PKCS#1 v1.5 padding if the error code of the application is\navailable.\n\nThat is a Bleichenbacher oracle (Bleichenbacher, CRYPTO '98): an\nadaptive-chosen-ciphertext side channel from which the attacker decrypts any\nRSA ciphertext to the victim's key or forges any PKCS#1 v1.5 signature under\nit.\n\n2. When the decryption API (CMS_decrypt(), PKCS7_decrypt()) is provided with\nthe recipient certificate, and the recipient is not found, a random\nkey is substituted.\n\nAn attacker who authors a message and is able to compare both error code and\nthe result of the decryption, can mount a Bleichenbacher oracle.\n\nWe are not aware of any applications that provide a remote attacker\nan opportunity to mount an attack described in these scenarios. We consider\nthe existence of such application very unlikely, and for this reason this\nCVE has been evaluated as Low severity.\n\nTo avoid these attacks, when RSA PKCS#1 v1.5 Key Transport is in use, the\ninvoked EVP_PKEY_decrypt() will use the implicit rejection mechanism described\nin draft-irtf-cfrg-rsa-guidance. In previous OpenSSL releases the implicit\nrejection was explicitly disabled.\n\nThe implicit rejection mechanism always returns a plaintext value,\nthe symmetric key. This result is deterministic for the ciphertext and the\nprivate key.  The length of the decryption result can happen to match the\nlength of the key of the symmetric cipher that was used for the content\nencryption. When a certificate is not provided, the last RecipientInfo\nproducing a key that looks valid will be used. It may cause getting garbage\ncontent on decryption. As a proper way to deal with this a recipient\ncertificate has to be provided to identify the particular RecipientInfo for\ndecryption.\n\nThe FIPS modules in 4.0, 3.6, 3.5, and 3.4 are not affected by this issue, as\nCMS and S/MIME processing happens outside the OpenSSL FIPS module boundary."
        },
        {
          "lang": "es",
          "value": "Resumen del problema: Las funciones CMS_decrypt y PKCS7_decrypt son vulnerables a un ataque de estilo Bleichenbacher cuando un atacante es capaz de proporcionar los mensajes CMS o S/MIME y observar el código de error y/o la salida del descifrado.\n\nResumen del impacto: El ataque de estilo Bleichenbacher permite a un atacante usar la aplicación vulnerable de la víctima como una forma de descifrar o firmar mensajes con la clave RSA privada de la víctima.\n\nEl ataque es posible en 2 variantes.\n\n1. La API de descifrado (CMS_decrypt(), PKCS7_decrypt()) se utiliza sin proporcionar el certificado del destinatario. En este caso, OpenSSL itera sobre cada KeyTransRecipientInfo (KTRI) sin detenerse en el primer éxito.\n\nUn atacante que crea un mensaje con dos entradas KTRI - la primera envolviendo una CEK real bajo la clave pública de la víctima, la segunda con un texto cifrado de sondeo arbitrario - obtiene la oportunidad de iterar la segunda KTRI para obtener un relleno PKCS#1 v1.5 válido si el código de error de la aplicación está disponible.\n\nEso es un oráculo de Bleichenbacher (Bleichenbacher, CRYPTO '98): un canal lateral de texto cifrado elegido adaptativo desde el cual el atacante descifra cualquier texto cifrado RSA a la clave de la víctima o falsifica cualquier firma PKCS#1 v1.5 bajo ella.\n\n2. Cuando la API de descifrado (CMS_decrypt(), PKCS7_decrypt()) se proporciona con el certificado del destinatario, y el destinatario no se encuentra, se sustituye una clave aleatoria.\n\nUn atacante que crea un mensaje y es capaz de comparar tanto el código de error como el resultado del descifrado, puede montar un oráculo de Bleichenbacher.\n\nNo tenemos conocimiento de ninguna aplicación que proporcione a un atacante remoto la oportunidad de montar un ataque descrito en estos escenarios. Consideramos muy improbable la existencia de dicha aplicación, y por esta razón este CVE ha sido evaluado como de severidad Baja.\n\nPara evitar estos ataques, cuando el transporte de clave RSA PKCS#1 v1.5 está en uso, la función EVP_PKEY_decrypt() invocada utilizará el mecanismo de rechazo implícito descrito en draft-irtf-cfrg-rsa-guidance. En versiones anteriores de OpenSSL, el rechazo implícito estaba explícitamente deshabilitado.\n\nEl mecanismo de rechazo implícito siempre devuelve un valor de texto plano, la clave simétrica. Este resultado es determinista para el texto cifrado y la clave privada. La longitud del resultado del descifrado puede coincidir con la longitud de la clave del cifrado simétrico que se utilizó para el cifrado del contenido. Cuando no se proporciona un certificado, se utilizará el último RecipientInfo que produzca una clave que parezca válida. Puede causar la obtención de contenido basura en el descifrado. Como una forma adecuada de lidiar con esto, se debe proporcionar un certificado de destinatario para identificar el RecipientInfo particular para el descifrado.\n\nLos módulos FIPS en 4.0, 3.6, 3.5 y 3.4 no se ven afectados por este problema, ya que el procesamiento de CMS y S/MIME ocurre fuera del límite del módulo FIPS de OpenSSL."
        }
      ],
      "references": [
        {
          "url": "https://github.com/openssl/openssl/commit/a2ca7b2d73e0ffc1eae183fe6e1741dac767cb4f",
          "source": "user@openssl.org",
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/openssl/openssl/commit/bbb151a83041705d9d001ed2f9c12f5523e1b54d",
          "source": "user@openssl.org",
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/openssl/openssl/commit/dd68364107a58841c0a2546812518b65d3a23abd",
          "source": "user@openssl.org",
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://github.com/openssl/openssl/commit/f04b377be3d821741c86d1f4bf84dee09f3d5c3e",
          "source": "user@openssl.org",
          "tags": [
            "Patch"
          ]
        },
        {
          "url": "https://openssl-library.org/news/secadv/20260609.txt",
          "source": "user@openssl.org",
          "tags": [
            "Vendor Advisory"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
            "type": "Secondary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
              "attack_vector": "NETWORK",
              "attack_complexity": "HIGH",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "UNCHANGED",
              "confidentiality_impact": "LOW",
              "integrity_impact": "NONE",
              "availability_impact": "NONE",
              "base_score": 3.7,
              "base_severity": "LOW",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 2.2,
            "impact_score": 1.4
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": null
      },
      "weaknesses": [
        {
          "source": "user@openssl.org",
          "type": "Secondary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-514"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "BF7E21E7-AEC0-4882-B1F1-2D056B506F22",
                  "version_start_including": "3.4.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "3.4.6"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "6B6B9930-C549-4D88-9784-AF32CCDDB87A",
                  "version_start_including": "3.5.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "3.5.7"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "D41B3C45-EC73-4DC8-989D-B2E2792E102F",
                  "version_start_including": "3.6.0",
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "3.6.3"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:*",
                  "match_criteria_id": "6E881B9A-1A0A-4BC0-8160-20C00561167D",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
            "vendor": "openssl",
            "product": "openssl",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "3.4.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "3.4.6",
            "affected_versions_first": "3.4.0",
            "affected_versions_last": "3.4.5"
          },
          {
            "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
            "vendor": "openssl",
            "product": "openssl",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "3.5.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "3.5.7",
            "affected_versions_first": "3.5.0",
            "affected_versions_last": "3.5.6"
          },
          {
            "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
            "vendor": "openssl",
            "product": "openssl",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "3.6.0",
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": "3.6.3",
            "affected_versions_first": "3.6.0",
            "affected_versions_last": "3.6.2"
          },
          {
            "criteria": "cpe:2.3:a:openssl:openssl:4.0.0:-:*:*:*:*:*:*",
            "vendor": "openssl",
            "product": "openssl",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "4.0.0",
            "affected_versions_last": "4.0.0"
          }
        ],
        "cwe": [
          {
            "id": 514,
            "owasptop10_2021": null,
            "name": "Covert Channel",
            "description": "A covert channel is a path that can be used to transfer information in a way not intended by the system's designers.",
            "capec_id": [
              463
            ],
            "scope": [
              "Access Control",
              "Confidentiality"
            ],
            "impact": [
              "Bypass Protection Mechanism",
              "Read Application Data"
            ],
            "detection_method": [
              "Architecture or Design Review"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.0058,
          "percentile": 0.46448,
          "date": "2026-09-23"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "3.1"
          ],
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "type": "Secondary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "attack_vector": "NETWORK",
            "attack_complexity": "HIGH",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "LOW",
            "vulnerable_system_integrity": "NONE",
            "vulnerable_system_availability": "NONE",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 3.7,
            "base_severity": "LOW"
          }
        }
      }
    },
    {
      "id": "CVE-2021-23839",
      "source_identifier": "user@openssl.org",
      "published": "2021-02-16T17:15:13Z",
      "last_modified": "2026-06-17T03:38:54Z",
      "status": "Modified",
      "evaluator_comment": null,
      "evaluator_solution": null,
      "evaluator_impact": null,
      "cisa_exploit_add": null,
      "cisa_action_due": null,
      "cisa_required_action": null,
      "cisa_vulnerability_name": null,
      "descriptions": [
        {
          "lang": "en",
          "value": "OpenSSL 1.0.2 supports SSLv2. If a client attempts to negotiate SSLv2 with a server that is configured to support both SSLv2 and more recent SSL and TLS versions then a check is made for a version rollback attack when unpadding an RSA signature. Clients that support SSL or TLS versions greater than SSLv2 are supposed to use a special form of padding. A server that supports greater than SSLv2 is supposed to reject connection attempts from a client where this special form of padding is present, because this indicates that a version rollback has occurred (i.e. both client and server support greater than SSLv2, and yet this is the version that is being requested). The implementation of this padding check inverted the logic so that the connection attempt is accepted if the padding is present, and rejected if it is absent. This means that such as server will accept a connection if a version rollback attack has occurred. Further the server will erroneously reject a connection if a normal SSLv2 connection attempt is made. Only OpenSSL 1.0.2 servers from version 1.0.2s to 1.0.2x are affected by this issue. In order to be vulnerable a 1.0.2 server must: 1) have configured SSLv2 support at compile time (this is off by default), 2) have configured SSLv2 support at runtime (this is off by default), 3) have configured SSLv2 ciphersuites (these are not in the default ciphersuite list) OpenSSL 1.1.1 does not have SSLv2 support and therefore is not vulnerable to this issue. The underlying error is in the implementation of the RSA_padding_check_SSLv23() function. This also affects the RSA_SSLV23_PADDING padding mode used by various other functions. Although 1.1.1 does not support SSLv2 the RSA_padding_check_SSLv23() function still exists, as does the RSA_SSLV23_PADDING padding mode. Applications that directly call that function or use that padding mode will encounter this issue. However since there is no support for the SSLv2 protocol in 1.1.1 this is considered a bug and not a security issue in that version. OpenSSL 1.0.2 is out of support and no longer receiving public updates. Premium support customers of OpenSSL 1.0.2 should upgrade to 1.0.2y. Other users should upgrade to 1.1.1j. Fixed in OpenSSL 1.0.2y (Affected 1.0.2s-1.0.2x)."
        },
        {
          "lang": "es",
          "value": "OpenSSL versión 1.0.2 soporta SSLv2. Si un cliente intenta negociar SSLv2 con un servidor que está configurado para soportar tanto SSLv2 como versiones más recientes de SSL y TLS, entonces se hace una comprobación de un ataque de retroceso de versión cuando se deshace una firma RSA. Los clientes que soportan versiones de SSL o TLS superiores a SSLv2 deben usar una forma especial de relleno. Un servidor que soporta una versión superior a SSLv2 debe rechazar los intentos de conexión de un cliente en el que esté presente esta forma especial de relleno, porque esto indica que se ha producido un retroceso de versión (es decir, tanto el cliente como el servidor soportan una versión superior a SSLv2, y sin embargo esta es la versión que se está requiriendo). La implementación de esta comprobación de padding invirtió la lógica para que el intento de conexión sea aceptado si el padding está presente, y rechazado si está ausente. Esto significa que tal servidor aceptará una conexión si se ha producido un ataque de retroceso de versión. Además, el servidor rechazará erróneamente una conexión si se realiza un intento de conexión SSLv2 normal. Sólo los servidores OpenSSL versión 1.0.2 desde la versión 1.0.2s hasta la 1.0.2x están afectados por este problema. Para ser vulnerable, un servidor versión 1.0.2 debe 1) haber configurado la compatibilidad con SSLv2 en tiempo de compilación (está desactivada por defecto), 2) haber configurado la compatibilidad con SSLv2 en tiempo de ejecución (está deshabilitada por defecto), 3) haber configurado los ciphersuites de SSLv2 (no están en la lista de ciphersuites por defecto) OpenSSL versión 1.1.1 no presenta compatibilidad con SSLv2 y, por tanto, no es vulnerable a este problema. El error subyacente está en la implementación de la función RSA_padding_check_SSLv23(). Esto también afecta al modo de relleno RSA_SSLV23_PADDING usado por otras funciones. Aunque la versión 1.1.1 no soporta SSLv2, la función RSA_padding_check_SSLv23() sigue existiendo, al igual que el modo de relleno RSA_SSLV23_PADDING. Las aplicaciones que llamen directamente a esa función o utilicen ese modo de relleno se encontrarán con este problema. Sin embargo, como no existe soporte para el protocolo SSLv2 en la versión 1.1.1, esto se considera un error y no un problema de seguridad en esa versión. OpenSSL versión 1.0.2 está fuera de soporte y ya no recibe actualizaciones públicas. Los clientes de soporte Premium de OpenSSL versión 1.0.2 deben actualizar a la versión 1.0.2y. Los demás usuarios deben actualizar a la versión 1.1.1j. Corregido en OpenSSL versión 1.0.2y (Afectó versiones 1.0.2s-1.0.2x)"
        }
      ],
      "references": [
        {
          "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf",
          "source": "user@openssl.org",
          "tags": [
            "Patch",
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://git.openssl.org/gitweb/?p=openssl.git%3Ba=commitdiff%3Bh=30919ab80a478f2d81f2e9acdcca3fa4740cd547",
          "source": "user@openssl.org",
          "tags": null
        },
        {
          "url": "https://kb.pulsesecure.net/articles/Pulse_Security_Advisories/SA44846",
          "source": "user@openssl.org",
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20210219-0009/",
          "source": "user@openssl.org",
          "tags": [
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://security.netapp.com/advisory/ntap-20240621-0006/",
          "source": "user@openssl.org",
          "tags": null
        },
        {
          "url": "https://www.openssl.org/news/secadv/20210216.txt",
          "source": "user@openssl.org",
          "tags": [
            "Vendor Advisory"
          ]
        },
        {
          "url": "https://www.oracle.com//security-alerts/cpujul2021.html",
          "source": "user@openssl.org",
          "tags": [
            "Patch",
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuApr2021.html",
          "source": "user@openssl.org",
          "tags": [
            "Patch",
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuapr2022.html",
          "source": "user@openssl.org",
          "tags": [
            "Patch",
            "Third Party Advisory"
          ]
        },
        {
          "url": "https://www.oracle.com/security-alerts/cpuoct2021.html",
          "source": "user@openssl.org",
          "tags": [
            "Patch",
            "Third Party Advisory"
          ]
        }
      ],
      "metrics": {
        "cvss_metric_v40": null,
        "cvss_metric_v31": [
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "3.1",
              "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
              "attack_vector": "NETWORK",
              "attack_complexity": "HIGH",
              "privileges_required": "NONE",
              "user_interaction": "NONE",
              "scope": "UNCHANGED",
              "confidentiality_impact": "NONE",
              "integrity_impact": "LOW",
              "availability_impact": "NONE",
              "base_score": 3.7,
              "base_severity": "LOW",
              "exploit_code_maturity": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "temporal_severity": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "modified_attack_vector": null,
              "modified_attack_complexity": null,
              "modified_privileges_required": null,
              "modified_user_interaction": null,
              "modified_scope": null,
              "modified_confidentiality_impact": null,
              "modified_integrity_impact": null,
              "modified_availability_impact": null,
              "environmental_score": null,
              "environmental_severity": null
            },
            "exploitability_score": 2.2,
            "impact_score": 1.4
          }
        ],
        "cvss_metric_v30": null,
        "cvss_metric_v2": [
          {
            "source": "user@nist.gov",
            "type": "Primary",
            "cvss_data": {
              "version": "2.0",
              "vector_string": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
              "access_vector": "NETWORK",
              "access_complexity": "MEDIUM",
              "authentication": "NONE",
              "confidentiality_impact": "NONE",
              "integrity_impact": "PARTIAL",
              "availability_impact": "NONE",
              "base_score": 4.3,
              "exploitability": null,
              "remediation_level": null,
              "report_confidence": null,
              "temporal_score": null,
              "collateral_damage_potential": null,
              "target_distribution": null,
              "confidentiality_requirement": null,
              "integrity_requirement": null,
              "availability_requirement": null,
              "environmental_score": null
            },
            "base_severity": "MEDIUM",
            "exploitability_score": 8.6,
            "impact_score": 2.9,
            "ac_insuf_info": false,
            "obtain_all_privilege": false,
            "obtain_user_privilege": false,
            "obtain_other_privilege": false,
            "user_interaction_required": false
          }
        ]
      },
      "weaknesses": [
        {
          "source": "user@nist.gov",
          "type": "Primary",
          "description": [
            {
              "lang": "en",
              "value": "CWE-327"
            }
          ]
        }
      ],
      "configurations": [
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "3E90DD3D-CF27-4D49-973A-86E03225027B",
                  "version_start_including": "1.0.2s",
                  "version_start_excluding": null,
                  "version_end_including": "1.0.2x",
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:oracle:business_intelligence:5.5.0.0.0:*:*:*:enterprise:*:*:*",
                  "match_criteria_id": "D40AD626-B23A-44A3-A6C0-1FFB4D647AE4",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:oracle:business_intelligence:5.9.0.0.0:*:*:*:enterprise:*:*:*",
                  "match_criteria_id": "B602F9E8-1580-436C-A26D-6E6F8121A583",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:*",
                  "match_criteria_id": "77C3DD16-1D81-40E1-B312-50FBD275507C",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*",
                  "match_criteria_id": "81DAC8C0-D342-44B5-9432-6B88D389584F",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:oracle:enterprise_manager_for_storage_management:13.4.0.0:*:*:*:*:*:*:*",
                  "match_criteria_id": "61516569-C48F-4362-B334-8CA10EDB0EC2",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:*",
                  "match_criteria_id": "B095CC03-7077-4A58-AB25-CC5380CDCE5A",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:oracle:graalvm:19.3.5:*:*:*:enterprise:*:*:*",
                  "match_criteria_id": "058C7C4B-D692-49DE-924A-C2725A8162D3",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:oracle:graalvm:20.3.1.2:*:*:*:community:*:*:*",
                  "match_criteria_id": "F325B4DE-1330-4DE2-B127-76FA14C3639B",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:oracle:graalvm:21.0.0.2:*:*:*:community:*:*:*",
                  "match_criteria_id": "CEDB365B-ABB3-4E62-B8C6-5E3454270855",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:oracle:jd_edwards_world_security:a9.4:*:*:*:*:*:*:*",
                  "match_criteria_id": "0B1CAD50-749F-4ADB-A046-BF3585677A58",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        },
        {
          "operator": null,
          "negate": null,
          "nodes": [
            {
              "operator": "OR",
              "negate": false,
              "cpe_match": [
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:siemens:sinec_ins:*:*:*:*:*:*:*:*",
                  "match_criteria_id": "C89891C1-DFD7-4E1F-80A9-7485D86A15B5",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": "1.0"
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:siemens:sinec_ins:1.0:-:*:*:*:*:*:*",
                  "match_criteria_id": "4664B195-AF14-4834-82B3-0B2C98020EB6",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                },
                {
                  "vulnerable": true,
                  "criteria": "cpe:2.3:a:siemens:sinec_ins:1.0:sp1:*:*:*:*:*:*",
                  "match_criteria_id": "75BC588E-CDF0-404E-AD61-02093A1DF343",
                  "version_start_including": null,
                  "version_start_excluding": null,
                  "version_end_including": null,
                  "version_end_excluding": null
                }
              ]
            }
          ]
        }
      ],
      "vendor_comments": null,
      "enrichment": {
        "cpe": [
          {
            "criteria": "cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:*",
            "vendor": "openssl",
            "product": "openssl",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": "1.0.2s",
            "version_start_excluding": null,
            "version_end_including": "1.0.2x",
            "version_end_excluding": null,
            "affected_versions_first": "1.0.2s",
            "affected_versions_last": "1.0.2x"
          },
          {
            "criteria": "cpe:2.3:a:oracle:business_intelligence:5.5.0.0.0:*:*:*:enterprise:*:*:*",
            "vendor": "oracle",
            "product": "business_intelligence",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "5.5.0.0.0",
            "affected_versions_last": "5.5.0.0.0"
          },
          {
            "criteria": "cpe:2.3:a:oracle:business_intelligence:5.9.0.0.0:*:*:*:enterprise:*:*:*",
            "vendor": "oracle",
            "product": "business_intelligence",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "5.9.0.0.0",
            "affected_versions_last": "5.9.0.0.0"
          },
          {
            "criteria": "cpe:2.3:a:oracle:business_intelligence:12.2.1.3.0:*:*:*:enterprise:*:*:*",
            "vendor": "oracle",
            "product": "business_intelligence",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "12.2.1.3.0",
            "affected_versions_last": "12.2.1.3.0"
          },
          {
            "criteria": "cpe:2.3:a:oracle:business_intelligence:12.2.1.4.0:*:*:*:enterprise:*:*:*",
            "vendor": "oracle",
            "product": "business_intelligence",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "12.2.1.4.0",
            "affected_versions_last": "12.2.1.4.0"
          },
          {
            "criteria": "cpe:2.3:a:oracle:enterprise_manager_for_storage_management:13.4.0.0:*:*:*:*:*:*:*",
            "vendor": "oracle",
            "product": "enterprise_manager_for_storage_management",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "13.4.0.0",
            "affected_versions_last": "13.4.0.0"
          },
          {
            "criteria": "cpe:2.3:a:oracle:enterprise_manager_ops_center:12.4.0.0:*:*:*:*:*:*:*",
            "vendor": "oracle",
            "product": "enterprise_manager_ops_center",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "12.4.0.0",
            "affected_versions_last": "12.4.0.0"
          },
          {
            "criteria": "cpe:2.3:a:oracle:graalvm:19.3.5:*:*:*:enterprise:*:*:*",
            "vendor": "oracle",
            "product": "graalvm",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "19.3.5",
            "affected_versions_last": "19.3.5"
          },
          {
            "criteria": "cpe:2.3:a:oracle:graalvm:20.3.1.2:*:*:*:community:*:*:*",
            "vendor": "oracle",
            "product": "graalvm",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "20.3.1.2",
            "affected_versions_last": "20.3.1.2"
          },
          {
            "criteria": "cpe:2.3:a:oracle:graalvm:21.0.0.2:*:*:*:community:*:*:*",
            "vendor": "oracle",
            "product": "graalvm",
            "product_type": "a",
            "vulnerable": true,
            "version_start_including": null,
            "version_start_excluding": null,
            "version_end_including": null,
            "version_end_excluding": null,
            "affected_versions_first": "21.0.0.2",
            "affected_versions_last": "21.0.0.2"
          }
        ],
        "cwe": [
          {
            "id": 327,
            "owasptop10_2021": "A02 Cryptographic Failures",
            "name": "Use of a Broken or Risky Cryptographic Algorithm",
            "description": "The product uses a broken or risky cryptographic algorithm or protocol.",
            "capec_id": [
              20,
              97,
              459,
              473,
              475,
              608,
              614
            ],
            "scope": [
              "Accountability",
              "Confidentiality",
              "Integrity",
              "Non-Repudiation"
            ],
            "impact": [
              "Hide Activities",
              "Modify Application Data",
              "Read Application Data"
            ],
            "detection_method": [
              "Architecture or Design Review",
              "Automated Analysis",
              "Automated Static Analysis",
              "Automated Static Analysis - Binary or Bytecode",
              "Automated Static Analysis - Source Code",
              "Dynamic Analysis with Automated Results Interpretation",
              "Dynamic Analysis with Manual Results Interpretation",
              "Manual Analysis",
              "Manual Static Analysis - Binary or Bytecode",
              "Manual Static Analysis - Source Code"
            ]
          }
        ],
        "epss_score": {
          "epss": 0.02961,
          "percentile": 0.86626,
          "date": "2026-09-23"
        },
        "cisa_kev": null,
        "vdeep_metric": {
          "available_versions": [
            "3.1",
            "2.0"
          ],
          "source": "user@nist.gov",
          "type": "Primary",
          "cvss_data": {
            "version": "3.1",
            "vector_string": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "attack_vector": "NETWORK",
            "attack_complexity": "HIGH",
            "attack_requirements": null,
            "privileges_required": "NONE",
            "user_interaction": "NONE",
            "vulnerable_system_confidentiality": "NONE",
            "vulnerable_system_integrity": "LOW",
            "vulnerable_system_availability": "NONE",
            "subsequent_system_confidentiality": null,
            "subsequent_system_integrity": null,
            "subsequent_system_availability": null,
            "exploit_maturity": null,
            "confidentiality_requirements": null,
            "integrity_requirements": null,
            "availability_requirements": null,
            "modified_attack_vector": null,
            "modified_attack_complexity": null,
            "modified_attack_requirements": null,
            "modified_privileges_required": null,
            "modified_user_interaction": null,
            "modified_vulnerable_system_confidentiality": null,
            "modified_vulnerable_system_integrity": null,
            "modified_vulnerable_system_availability": null,
            "modified_subsequent_system_confidentiality": null,
            "modified_subsequent_system_integrity": null,
            "modified_subsequent_system_availability": null,
            "safety": null,
            "automatable": null,
            "recovery": null,
            "value_density": null,
            "vulnerability_response_effort": null,
            "provider_urgency": null,
            "base_score": 3.7,
            "base_severity": "LOW"
          }
        }
      }
    }
  ]
}
```

## Related Examples

- [Sort by Deepinfo Score: Lowest First](/reference/vulnerability/search/examples/sort-base-score/)
- [MOVEit Transfer CVEs Other Than the 2023 Mass Exploitation](/reference/vulnerability/search/examples/moveit-except-cve-2023-34362/)
- [Sort by Product](/reference/vulnerability/search/examples/sort-enrichment-cpe-product/)
- [Sort by Vendor](/reference/vulnerability/search/examples/sort-enrichment-cpe-vendor/)
- [Sort by Id: Newest Log4j CVEs First](/reference/vulnerability/search/examples/sort-id/)
- [Microsoft CVEs of 2024 With a High EPSS](/reference/vulnerability/search/examples/microsoft-2024-high-epss/)
