cbcvebase.

Oracle Application Express vulnerabilities

47 known vulnerabilities affecting oracle/application_express.

Total CVEs
47
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
CRITICAL4HIGH2MEDIUM41

Vulnerabilities

Page 3 of 3
CVE-2020-2973P4MEDIUMCVSS 5.4≥ 5.1, ≤ 19.22020-07-15
CVE-2020-2973 [MEDIUM] CVE-2020-2973: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person o
nvd
CVE-2020-2976P4MEDIUMCVSS 5.4≥ 5.1, ≤ 19.22020-07-15
CVE-2020-2976 [MEDIUM] CVE-2020-2976: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person o
nvd
CVE-2020-2972P4MEDIUMCVSS 5.4≥ 5.1, ≤ 19.22020-07-15
CVE-2020-2972 [MEDIUM] CWE-79 CVE-2020-2972: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a p
nvd
CVE-2020-2513P4MEDIUMCVSS 5.4≥ 5.1, ≤ 19.22020-07-15
CVE-2020-2513 [MEDIUM] CWE-79 CVE-2020-2513: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having SQL Workshop privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a p
nvd
CVE-2021-2460P4MEDIUMCVSS 5.4fixed in 21.1.0.00.042021-07-21
CVE-2021-2460 [MEDIUM] CVE-2021-2460: Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. T Vulnerability in the Oracle Application Express Data Reporter component of Oracle Database Server. The supported version that is affected is Prior to 21.1.0.00.04. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express Data Reporter. Successful a
nvd
CVE-2020-2977P4MEDIUMCVSS 4.6≥ 5.1, ≤ 19.22020-07-15
CVE-2020-2977 [MEDIUM] CVE-2020-2977: Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versi Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a pe
nvd
CVE-2020-2514P4MEDIUMCVSS 4.6fixed in 19.22020-04-15
CVE-2020-2514 [MEDIUM] CVE-2020-2514: Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported v Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported version that is affected is Prior to 19.2. Easily exploitable vulnerability allows low privileged attacker having End User Role privilege with network access via HTTPS to compromise Oracle Application Express. Successful attacks require human interaction from a
nvd
Oracle Application Express vulnerabilities | cvebase