Oracle Applications Framework vulnerabilities
27 known vulnerabilities affecting oracle/applications_framework.
Total CVEs
27
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH7MEDIUM18LOW1
Vulnerabilities
Page 2 of 2
CVE-2020-2666MEDIUMCVSS 5.3≥ 12.2.5, ≤ 12.2.92020-01-15
CVE-2020-2666 [MEDIUM] CVE-2020-2666: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: At
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload). Supported versions that are affected are 12.2.5-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Applications Framework. Successful attacks of this vulnerabilit
nvd
CVE-2020-2566MEDIUMCVSS 4.7≥ 12.2.3, ≤ 12.2.9v12.1.32020-01-15
CVE-2020-2566 [MEDIUM] CVE-2020-2566: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: At
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Attachments / File Upload). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Applications Framework. Successful attacks require h
nvd
CVE-2019-2682HIGHCVSS 8.2v12.1.3v12.2.3+5 more2019-04-23
CVE-2019-2682 [HIGH] CVE-2019-2682: Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponen
Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Attachments / File Upload). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Fram
nvd
CVE-2018-3243HIGHCVSS 8.2v12.1.3v12.2.3+3 more2018-10-17
CVE-2018-3243 [HIGH] CVE-2018-3243: Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponen
Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: None). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require hum
nvd
CVE-2018-2971MEDIUMCVSS 4.3v12.1.3v12.2.3+4 more2018-10-17
CVE-2018-2971 [MEDIUM] CVE-2018-2971: Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponen
Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: REST Services). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful a
nvd
CVE-2017-3528MEDIUMCVSS 5.4PoCv12.1.3v12.2.3+3 more2017-04-24
CVE-2017-3528 [MEDIUM] CWE-601 CVE-2017-3528: Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponen
Vulnerability in the Oracle Applications Framework component of Oracle E-Business Suite (subcomponent: Popup windows (lists of values, datepicker, etc.)). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Orac
nvd
CVE-2016-3447MEDIUMCVSS 6.9v12.1.3v12.2.3+2 more2016-04-21
CVE-2016-3447 [MEDIUM] CVE-2016-3447: Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to OAF Core.
nvd
← Previous2 / 2