Oracle E-Business Suite vulnerabilities
345 known vulnerabilities affecting oracle/e-business_suite.
Total CVEs
345
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL56HIGH56MEDIUM191LOW42
Vulnerabilities
Page 1 of 18
CVE-2022-21587P1CRITICALCVSS 9.8KEVPoCRansomware≥ 12.2.3, ≤ 12.2.112022-10-18
CVE-2022-21587 [CRITICAL] CWE-306 CVE-2022-21587: Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks o
nvd
CVE-2026-46817P1CRITICALCVSS 9.8KEVRansomware≥ 12.2.3, ≤ 12.2.152026-05-28
CVE-2026-46817 [CRITICAL] CWE-269 CVE-2026-46817: Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmissio
Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover
nvd
CVE-2021-45105P1MEDIUMCVSS 5.9ExploitedPoCRansomwarev12.22021-12-18
CVE-2021-45105 [MEDIUM] CWE-20 CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
nvd
CVE-2022-21500P1HIGHCVSS 7.5ExploitedPoCv12.22022-05-20
CVE-2022-21500 [HIGH] CVE-2022-21500: Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is
Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access
nvd
CVE-2016-0457P2MEDIUMCVSS 5.0Exploitedv12.1v12.22016-01-21
CVE-2016-0457 [MEDIUM] CVE-2016-0457: Unspecified vulnerability in the Application Mgmt Pack for E-Business Suite component in Oracle E-Bu
Unspecified vulnerability in the Application Mgmt Pack for E-Business Suite component in Oracle E-Business Suite 12.1 and 12.2 allows remote attackers to affect confidentiality via vectors related to REST Framework, a different vulnerability than CVE-2016-0456. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-part
nvd
CVE-2004-1364P3HIGHCVSS 8.5PoCv11.5.1v11.5.2+7 more2004-08-04
CVE-2004-1364 [HIGH] CWE-22 CVE-2004-1364: Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access
Directory traversal vulnerability in extproc in Oracle 9i and 10g allows remote attackers to access arbitrary libraries outside of the $ORACLE_HOME\bin directory.
nvd
CVE-2025-30727P2CRITICALCVSS 9.8≥ 12.2.3, ≤ 12.2.142025-04-15
CVE-2025-30727 [CRITICAL] CWE-306 CVE-2025-30727: Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module)
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks of this vulnerability can result in takeover
nvd
CVE-2026-46819P2CRITICALCVSS 9.1≥ 12.2.3, ≤ 12.2.152026-05-28
CVE-2026-46819 [CRITICAL] CWE-284 CVE-2026-46819: Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (compo
Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Internet Procurement Connector. Successful attack
nvd
CVE-2018-2656P2CRITICALCVSS 9.1v12.1.1v12.1.2+6 more2018-01-18
CVE-2018-2656 [CRITICAL] CVE-2018-2656: Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Data
Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Data Manager Server). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Ledger. Succ
nvd
CVE-2019-2489P2CRITICALCVSS 9.1v12.1.3v12.2.3+5 more2019-01-16
CVE-2019-2489 [CRITICAL] CVE-2019-2489: Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponen
Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: OCM Query). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Succe
nvd
CVE-2019-2453P2CRITICALCVSS 9.1v12.1.1v12.1.2+1 more2019-01-16
CVE-2019-2453 [CRITICAL] CVE-2019-2453: Vulnerability in the Oracle Performance Management component of Oracle E-Business Suite (subcomponen
Vulnerability in the Oracle Performance Management component of Oracle E-Business Suite (subcomponent: Performance Management Plan). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Performance Management. Successful attacks
nvd
CVE-2013-0397P3MEDIUMCVSS 6.4PoCv11.5.10.2v12.0.6+1 more2013-01-17
CVE-2013-0397 [MEDIUM] CVE-2013-0397: Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite
Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Diagnostics.
nvd
CVE-2026-46826P2HIGHCVSS 8.8≥ 12.2.3, ≤ 12.2.152026-05-28
CVE-2026-46826 [HIGH] CWE-306 CVE-2026-46826: Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operatio
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTPS to compromise Oracle Payroll. Successful attacks of this vulnerability can result in takeover of
nvd
CVE-2026-46837P2HIGHCVSS 8.8≥ 12.2.9, ≤ 12.2.152026-05-28
CVE-2026-46837 [HIGH] CWE-269 CVE-2026-46837: Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Securi
Vulnerability in the Oracle Flow Manufacturing product of Oracle E-Business Suite (component: Security). Supported versions that are affected are 12.2.9-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via SQL to compromise Oracle Flow Manufacturing. Successful attacks of this vulnerability can result in tak
nvd
CVE-2026-46827P2HIGHCVSS 8.8≥ 12.2.3, ≤ 12.2.152026-05-28
CVE-2026-46827 [HIGH] CWE-269 CVE-2026-46827: Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Mana
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in takeover of
nvd
CVE-2026-47033P3HIGHCVSS 8.5≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-47033 [HIGH] CWE-284 CVE-2026-47033: Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Int
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. While the vulnerability is in Oracle C
nvd
CVE-2026-61338P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-61338 [HIGH] CWE-284 CVE-2026-61338: Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Int
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability
nvd
CVE-2026-60857P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-60857 [HIGH] CWE-284 CVE-2026-60857: Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Int
Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerability
nvd
CVE-2026-46828P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.152026-05-28
CVE-2026-46828 [HIGH] CWE-284 CVE-2026-46828: Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operatio
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Payroll. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2024-21277P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.132024-10-15
CVE-2024-21277 [HIGH] CWE-863 CVE-2024-21277: Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (compon
Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Device Integration). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle MES for Process Manufacturing. Successful attacks of thi
nvd
1 / 18Next →