Oracle Applications Framework vulnerabilities
28 known vulnerabilities affecting oracle/applications_framework.
Total CVEs
28
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH7MEDIUM19LOW1
Vulnerabilities
Page 2 of 2
CVE-2022-21477P4MEDIUMCVSS 5.4≥ 12.2.6, ≤ 12.2.112022-04-19
CVE-2022-21477 [MEDIUM] CVE-2022-21477: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: At
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments, File Upload). Supported versions that are affected are 12.2.6-12.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human intera
nvd
CVE-2026-34298P4MEDIUMCVSS 4.7≥ 12.2.9, ≤ 12.2.152026-04-21
CVE-2026-34298 [MEDIUM] CWE-284 CVE-2026-34298: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Pe
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerabilit
nvd
CVE-2020-14746P4MEDIUMCVSS 4.7≥ 12.2.3, ≤ 12.2.10v12.1.32020-10-21
CVE-2020-14746 [MEDIUM] CVE-2020-14746: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Po
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Popup windows). Supported versions that are affected are 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human int
nvd
CVE-2025-53064P4MEDIUMCVSS 4.3≥ 12.2.3, ≤ 12.2.142025-10-21
CVE-2025-53064 [MEDIUM] CWE-284 CVE-2025-53064: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Pe
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability
nvd
CVE-2025-53071P4MEDIUMCVSS 4.3≥ 12.2.3, ≤ 12.2.142025-10-21
CVE-2025-53071 [MEDIUM] CWE-284 CVE-2025-53071: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Up
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerabil
nvd
CVE-2020-2566P4MEDIUMCVSS 4.7≥ 12.2.3, ≤ 12.2.9v12.1.32020-01-15
CVE-2020-2566 [MEDIUM] CVE-2020-2566: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: At
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Applications Framework. Successful attacks require h
nvd
CVE-2018-2971P4MEDIUMCVSS 4.3v12.1.3v12.2.3+4 more2018-10-17
CVE-2018-2971 [MEDIUM] CVE-2018-2971: Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponen
Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: REST Services). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful a
nvd
CVE-2020-14590P4LOWCVSS 2.7≥ 12.2.3, ≤ 12.2.9v12.1.32020-07-15
CVE-2020-14590 [LOW] CVE-2020-14590: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Pa
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Page Request). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability ca
nvd
← Previous2 / 2