Oracle Application Object Library vulnerabilities
31 known vulnerabilities affecting oracle/application_object_library.
Total CVEs
31
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
HIGH6MEDIUM24LOW1
Vulnerabilities
Page 1 of 2
CVE-2017-10246P2HIGHCVSS 8.2PoCv12.1.3v12.2.3+3 more2017-08-08
CVE-2017-10246 [HIGH] CVE-2017-10246: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: iHelp). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks
nvd
CVE-2017-10328P3HIGHCVSS 7.5v12.1.3v12.2.3+4 more2017-10-19
CVE-2017-10328 [HIGH] CWE-200 CVE-2017-10328: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Diagnostics). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Librar
nvd
CVE-2021-2314P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.10v12.1.32021-04-22
CVE-2021-2314 [HIGH] CVE-2021-2314: Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Profiles). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability
nvd
CVE-2017-10177P3HIGHCVSS 8.1v12.2.62017-08-08
CVE-2017-10177 [HIGH] CVE-2017-10177: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Flexfields). The supported version that is affected is 12.2.6. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can resu
nvd
CVE-2018-3138P3HIGHCVSS 8.2v12.1.3v12.2.3+4 more2018-10-17
CVE-2018-3138 [HIGH] CVE-2018-3138: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Attachments / File Upload). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Li
nvd
CVE-2025-30730P3HIGHCVSS 7.5≥ 12.2.5, ≤ 12.2.142025-04-15
CVE-2025-30730 [HIGH] CWE-400 CVE-2025-30730: Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.5-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can
nvd
CVE-2024-20929P3MEDIUMCVSS 6.5≥ 12.2.3, ≤ 12.2.132024-02-17
CVE-2024-20929 [MEDIUM] CWE-284 CVE-2024-20929: Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: DB Privileges). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulner
nvd
CVE-2016-0589P4MEDIUMCVSS 6.4v11.5.10.22016-01-21
CVE-2016-0589 [MEDIUM] CVE-2016-0589: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2016-0576P4MEDIUMCVSS 6.4v11.5.10.22016-01-21
CVE-2016-0576 [MEDIUM] CVE-2016-0576: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality and integrity via vectors related to ICX LOVs.
nvd
CVE-2018-3244P4MEDIUMCVSS 5.3v12.1.3v12.2.3+4 more2018-10-17
CVE-2018-3244 [MEDIUM] CVE-2018-3244: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Attachments / File Upload). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object
nvd
CVE-2023-21978P4MEDIUMCVSS 6.5≥ 12.2.3, ≤ 12.2.112023-04-18
CVE-2023-21978 [MEDIUM] CVE-2023-21978: Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: GUI). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks require human interaction from a
nvd
CVE-2017-10331P4MEDIUMCVSS 5.3v12.1.3v12.2.3+4 more2017-10-19
CVE-2017-10331 [MEDIUM] CWE-200 CVE-2017-10331: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Diagnostics). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Libr
nvd
CVE-2017-10244P4MEDIUMCVSS 5.3v12.1.3v12.2.3+3 more2017-08-08
CVE-2017-10244 [MEDIUM] CVE-2017-10244: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Attachments). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful
nvd
CVE-2025-30726P4MEDIUMCVSS 5.3≥ 12.2.3, ≤ 12.2.142025-04-15
CVE-2025-30726 [MEDIUM] CWE-284 CVE-2025-30726: Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability c
nvd
CVE-2025-30732P4MEDIUMCVSS 6.1≥ 12.2.3, ≤ 12.2.142025-04-15
CVE-2025-30732 [MEDIUM] CWE-284 CVE-2025-30732: Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks require human interacti
nvd
CVE-2017-3556P4MEDIUMCVSS 5.3v12.1.3v12.2.3+3 more2017-04-24
CVE-2017-3556 [MEDIUM] CWE-200 CVE-2017-3556: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: File Management). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library.
nvd
CVE-2016-3545P4MEDIUMCVSS 5.3v12.1.3v12.2.3+2 more2016-07-21
CVE-2016-3545 [MEDIUM] CVE-2016-3545: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality via vectors related to Web based help screens.
nvd
CVE-2020-14635P4MEDIUMCVSS 5.3≥ 12.2.5, ≤ 12.2.92020-07-15
CVE-2020-14635 [MEDIUM] CVE-2020-14635: Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Logging). Supported versions that are affected are 12.2.5-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can res
nvd
CVE-2024-21128P4MEDIUMCVSS 5.4≥ 12.2.6, ≤ 12.2.132024-07-16
CVE-2024-21128 [MEDIUM] CVE-2024-21128: Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: APIs). Supported versions that are affected are 12.2.6-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks require human interaction from a
nvd
CVE-2017-3246P4MEDIUMCVSS 6.0v12.1.3v12.2.3+3 more2017-01-27
CVE-2017-3246 [MEDIUM] CVE-2017-3246: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Patching). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Application Object Library executes to compromis
nvd
1 / 2Next →