Oracle Application Object Library vulnerabilities
40 known vulnerabilities affecting oracle/application_object_library.
Total CVEs
40
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM28LOW1
Vulnerabilities
Page 2 of 2
CVE-2017-10244P4MEDIUMCVSS 5.3v12.1.3v12.2.3+3 more2017-08-08
CVE-2017-10244 [MEDIUM] CVE-2017-10244: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Attachments). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful
nvd
CVE-2026-61111P4MEDIUMCVSS 6.5≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61111 [MEDIUM] CWE-284 CVE-2026-61111: Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Application Object Library executes to compromise Oracle Application Object
nvd
CVE-2017-3556P4MEDIUMCVSS 5.3v12.1.3v12.2.3+3 more2017-04-24
CVE-2017-3556 [MEDIUM] CWE-200 CVE-2017-3556: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: File Management). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library.
nvd
CVE-2025-30726P4MEDIUMCVSS 5.3≥ 12.2.3, ≤ 12.2.142025-04-15
CVE-2025-30726 [MEDIUM] CWE-284 CVE-2025-30726: Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability c
nvd
CVE-2016-3545P4MEDIUMCVSS 5.3v12.1.3v12.2.3+2 more2016-07-21
CVE-2016-3545 [MEDIUM] CVE-2016-3545: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality via vectors related to Web based help screens.
nvd
CVE-2025-30732P4MEDIUMCVSS 6.1≥ 12.2.3, ≤ 12.2.142025-04-15
CVE-2025-30732 [MEDIUM] CWE-284 CVE-2025-30732: Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Core). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks require human interacti
nvd
CVE-2020-14635P4MEDIUMCVSS 5.3≥ 12.2.5, ≤ 12.2.92020-07-15
CVE-2020-14635 [MEDIUM] CVE-2020-14635: Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Logging). Supported versions that are affected are 12.2.5-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can res
nvd
CVE-2024-21128P4MEDIUMCVSS 5.4≥ 12.2.6, ≤ 12.2.132024-07-16
CVE-2024-21128 [MEDIUM] CVE-2024-21128: Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: APIs). Supported versions that are affected are 12.2.6-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks require human interaction from a
nvd
CVE-2017-3246P4MEDIUMCVSS 6.0v12.1.3v12.2.3+3 more2017-01-27
CVE-2017-3246 [MEDIUM] CVE-2017-3246: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Patching). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Application Object Library executes to compromis
nvd
CVE-2019-3027P4MEDIUMCVSS 5.3≥ 12.2.5, ≤ 12.2.92019-10-16
CVE-2019-3027 [MEDIUM] CVE-2019-3027: Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Login Help). Supported versions that are affected are 12.2.5-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerability can re
nvd
CVE-2024-20915P4MEDIUMCVSS 5.3≥ 12.2.3, ≤ 12.2.132024-02-17
CVE-2024-20915 [MEDIUM] CWE-444 CVE-2024-20915: Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Login - SSO). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of this vulnerab
nvd
CVE-2016-0697P4MEDIUMCVSS 6.0v12.1.3v12.2.3+2 more2016-04-21
CVE-2016-0697 [MEDIUM] CVE-2016-0697: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows local users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2016-0585P4MEDIUMCVSS 5.0v11.5.10.22016-01-21
CVE-2016-0585 [MEDIUM] CVE-2016-0585: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect availability via vectors related to ICX Error.
nvd
CVE-2016-3434P4MEDIUMCVSS 4.7v12.1.3v12.2.3+2 more2016-04-21
CVE-2016-3434 [MEDIUM] CVE-2016-3434: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect integrity via vectors related to Logout.
nvd
CVE-2019-2621P4MEDIUMCVSS 4.7v12.1.3v12.2.3+5 more2019-04-23
CVE-2019-2621 [MEDIUM] CVE-2019-2621: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Diagnostics). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Librar
nvd
CVE-2020-14840P4MEDIUMCVSS 4.7≥ 12.2.3, ≤ 12.2.10v12.1.32020-10-21
CVE-2020-14840 [MEDIUM] CVE-2020-14840: Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks require hum
nvd
CVE-2020-14554P4MEDIUMCVSS 4.7≥ 12.2.3, ≤ 12.2.8v12.1.32020-07-15
CVE-2020-14554 [MEDIUM] CVE-2020-14554: Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component
Vulnerability in the Oracle Application Object Library product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks require human
nvd
CVE-2016-0520P4MEDIUMCVSS 4.3v11.5.10.22016-01-21
CVE-2016-0520 [MEDIUM] CVE-2016-0520: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via vectors related to Java APIs.
nvd
CVE-2016-0586P4MEDIUMCVSS 4.3v11.5.10.22016-01-21
CVE-2016-0586 [MEDIUM] CVE-2016-0586: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su
Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect integrity via unknown vectors related to iHelp.
nvd
CVE-2019-2761P4LOWCVSS 3.7≥ 12.2.3, ≤ 12.2.8v12.1.32019-07-23
CVE-2019-2761 [LOW] CVE-2019-2761: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp
Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Attachments / File Upload). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.8. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful atta
nvd
← Previous2 / 2