Oracle Common Applications vulnerabilities

16 known vulnerabilities affecting oracle/common_applications.

Total CVEs
16
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH10MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2025-30716HIGHCVSS 7.5≥ 12.2.3, ≤ 12.2.142025-04-15
CVE-2025-30716 [HIGH] CWE-862 CVE-2025-30716: Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM U Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications. Successful attacks of this vulner
nvd
CVE-2024-20947MEDIUMCVSS 5.4≥ 12.2.3, ≤ 12.2.132024-02-17
CVE-2024-20947 [MEDIUM] CVE-2024-20947: Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM U Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications. Successful attacks require human interac
nvd
CVE-2021-2436HIGHCVSS 8.2≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.102021-07-21
CVE-2021-2436 [HIGH] CVE-2021-2436: Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM U Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications. Successful attacks requir
nvd
CVE-2021-2093HIGHCVSS 8.2≥ 12.1.1, ≤ 12.1.3≥ 12.2.3, ≤ 12.2.102021-01-20
CVE-2021-2093 [HIGH] CVE-2021-2093: Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM U Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications. Successful attacks requir
nvd
CVE-2020-14688HIGHCVSS 8.2≥ 12.2.3, ≤ 12.2.9v12.1.32020-07-15
CVE-2020-14688 [HIGH] CVE-2020-14688: Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM U Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications. Successful attacks require huma
nvd
CVE-2020-14717MEDIUMCVSS 4.7≥ 12.2.3, ≤ 12.2.9v12.1.32020-07-15
CVE-2020-14717 [MEDIUM] CVE-2020-14717: Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM U Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications. Successful attacks require hu
nvd
CVE-2020-14716MEDIUMCVSS 4.7≥ 12.2.3, ≤ 12.2.9v12.1.32020-07-15
CVE-2020-14716 [MEDIUM] CVE-2020-14716: Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM U Vulnerability in the Oracle Common Applications product of Oracle E-Business Suite (component: CRM User Management Framework). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications. Successful attacks require hu
nvd
CVE-2019-2665HIGHCVSS 8.2v12.1.3v12.2.3+5 more2019-04-23
CVE-2019-2665 [HIGH] CVE-2019-2665: Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: CRM User Management Framework). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applicatio
nvd
CVE-2017-10330CRITICALCVSS 9.1v12.1.3v12.2.3+4 more2017-10-19
CVE-2017-10330 [CRITICAL] CVE-2017-10330: Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: Gantt Server). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications. Successful atta
nvd
CVE-2017-10113HIGHCVSS 8.2v12.1.3v12.2.3+3 more2017-08-08
CVE-2017-10113 [HIGH] CVE-2017-10113: Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: CRM User Management Framework). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications. Successful
nvd
CVE-2017-3328HIGHCVSS 8.2v12.1.1v12.1.2+5 more2017-01-27
CVE-2017-3328 [HIGH] CVE-2017-3328: Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: Resources Module). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications. Successfu
nvd
CVE-2017-3443HIGHCVSS 8.2v12.1.1v12.1.2+5 more2017-01-27
CVE-2017-3443 [HIGH] CVE-2017-3443: Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications. Successful
cvelistv5nvd
CVE-2017-3326HIGHCVSS 8.2v12.1.1v12.1.2+5 more2017-01-27
CVE-2017-3326 [HIGH] CVE-2017-3326: Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: Role Summary). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications. Successful at
cvelistv5nvd
CVE-2017-3327HIGHCVSS 8.2v12.1.1v12.1.2+5 more2017-01-27
CVE-2017-3327 [HIGH] CVE-2017-3327: Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: Vulnerability in the Oracle Common Applications component of Oracle E-Business Suite (subcomponent: Resources Module). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Common Applications. Successfu
cvelistv5nvd
CVE-2016-5575MEDIUMCVSS 5.3v12.1.1v12.1.2+5 more2016-10-25
CVE-2016-5575 [MEDIUM] CWE-200 CVE-2016-5575: Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Unspecified vulnerability in the Oracle Common Applications Calendar component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote attackers to affect confidentiality via vectors related to Resources Module.
nvd
CVE-2016-0562MEDIUMCVSS 4.0v11.5.10.2v12.1.1+2 more2016-01-21
CVE-2016-0562 [MEDIUM] CVE-2016-0562: Unspecified vulnerability in the Oracle Common Applications component in Oracle E-Business Suite 11. Unspecified vulnerability in the Oracle Common Applications component in Oracle E-Business Suite 11.5.10.2, 12.1.1, 12.1.2, and 12.1.3 allows remote authenticated users to affect integrity via vectors related to CRM User Management Framework.
nvd