cbcvebase.

Oracle E-Business Suite vulnerabilities

345 known vulnerabilities affecting oracle/e-business_suite.

Total CVEs
345
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL56HIGH56MEDIUM191LOW42

Vulnerabilities

Page 11 of 18
CVE-2009-1980P4MEDIUMCVSS 6.0v11.5.10.2v12.0.6+1 more2009-07-14
CVE-2009-1980 [MEDIUM] CVE-2009-1980: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2014-2482P4MEDIUMCVSS 5.5v12.1.3v12.2.2+1 more2014-07-17
CVE-2014-2482 [MEDIUM] CVE-2014-2482: Unspecified vulnerability in the Oracle Concurrent Processing component in Oracle E-Business Suite 1 Unspecified vulnerability in the Oracle Concurrent Processing component in Oracle E-Business Suite 12.1.3, 12.2.2, and 12.2.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2014-0398P4MEDIUMCVSS 5.0v11.5.10.2v12.0.6+2 more2014-01-15
CVE-2014-0398 [MEDIUM] CVE-2014-0398: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, and 12.2.2 allows remote attackers to affect confidentiality via unknown vectors related to Discoverer.
nvd
CVE-2012-3171P4MEDIUMCVSS 5.0v11.5.10.2v12.0.6+1 more2012-10-17
CVE-2012-3171 [MEDIUM] CVE-2012-3171: Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors related to Autoconfig Templates.
nvd
CVE-2013-5792P4MEDIUMCVSS 5.0v12.12013-10-16
CVE-2013-5792 [MEDIUM] CVE-2013-5792: Unspecified vulnerability in the Techstack component in Oracle E-Business Suite 12.1 allows remote a Unspecified vulnerability in the Techstack component in Oracle E-Business Suite 12.1 allows remote attackers to affect confidentiality via unknown vectors related to Apache.
nvd
CVE-2018-2635P4MEDIUMCVSS 4.8v12.1.3v12.2.3+4 more2018-01-18
CVE-2018-2635 [MEDIUM] CVE-2018-2635: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Login). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successfu
nvd
CVE-2015-2565P4MEDIUMCVSS 4.3v11.5.10.2v12.0.4+4 more2015-04-16
CVE-2015-2565 [MEDIUM] CVE-2015-2565: Unspecified vulnerability in the Oracle Installed Base component in Oracle E-Business Suite 11.5.10. Unspecified vulnerability in the Oracle Installed Base component in Oracle E-Business Suite 11.5.10.2, 12.0.4, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect integrity via unknown vectors related to Create Item Instance.
nvd
CVE-2015-0447P4MEDIUMCVSS 4.3v11.5.10.2v12.0.6+3 more2015-04-16
CVE-2015-0447 [MEDIUM] CVE-2015-0447: Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality via vectors related to Configurator DMZ rules.
nvd
CVE-2019-2546P4MEDIUMCVSS 4.3v12.1.1v12.1.2+7 more2019-01-16
CVE-2019-2546 [MEDIUM] CVE-2019-2546: Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: SQL Extensions). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications
nvd
CVE-2008-2606P4MEDIUMCVSS 6.5v12.0.42008-07-15
CVE-2008-2606 [MEDIUM] CVE-2008-2606: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.4 has unknown impact and remote authenticated attack vectors, a different vulnerability than CVE-2008-2586.
nvd
CVE-2026-62489P4MEDIUMCVSS 4.2≥ 12.2.3, ≤ 12.2.152026-07-21
CVE-2026-62489 [MEDIUM] CWE-284 CVE-2026-62489: Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Int Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contracts Integration. Successful attacks of this vulnerabi
nvd
CVE-2010-0915P4MEDIUMCVSS 5.5v11.5.10.2v12.0.6+1 more2010-07-13
CVE-2010-0915 [MEDIUM] CVE-2010-0915: Unspecified vulnerability in the Oracle Advanced Product Catalog component in Oracle E-Business Suit Unspecified vulnerability in the Oracle Advanced Product Catalog component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2012-3218P4MEDIUMCVSS 5.5v11.5.10.2v12.0.6+1 more2013-01-17
CVE-2012-3218 [MEDIUM] CVE-2012-3218: Unspecified vulnerability in the Human Resources component in Oracle E-Business Suite 11.5.10.2, 12. Unspecified vulnerability in the Human Resources component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Security Groups.
nvd
CVE-2012-0535P4MEDIUMCVSS 5.0v12.0.6v12.1.32012-05-03
CVE-2012-0535 [MEDIUM] CVE-2012-0535: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors related to Change Password Page.
nvd
CVE-2015-4854P4MEDIUMCVSS 4.3v12.0.6v12.1.3+2 more2015-10-21
CVE-2015-4854 [MEDIUM] CVE-2015-4854: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6, 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via unknown vectors related to Single Signon. NOTE: the previous information is from the October 2015 CPU. Oracle has not commented on third-party claims that this issue is a cro
nvd
CVE-2012-3222P4MEDIUMCVSS 5.0v11.5.10.2v12.0.6+3 more2012-10-17
CVE-2012-3222 [MEDIUM] CVE-2012-3222: Unspecified vulnerability in the Oracle iRecruitment component in Oracle E-Business Suite 11.5.10.2, Unspecified vulnerability in the Oracle iRecruitment component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.1, 12.1.2, and 12.1.3 allows remote attackers to affect availability via unknown vectors related to Signon.
nvd
CVE-2013-2388P4MEDIUMCVSS 5.0v11.5.10.2v12.0.6+1 more2013-04-17
CVE-2013-2388 [MEDIUM] CVE-2013-2388: Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.3 allows remote attackers to affect availability via unknown vectors related to Mid Tier File Management.
nvd
CVE-2010-0869P4MEDIUMCVSS 4.3v5.5.05.07v5.5.06.00+1 more2010-04-13
CVE-2010-0869 [MEDIUM] CVE-2010-0869: Unspecified vulnerability in the Oracle Transportation Management component in Oracle E-Business Sui Unspecified vulnerability in the Oracle Transportation Management component in Oracle E-Business Suite 5.5.05.07, 5.5.06.00, and 6.0.03 allows remote attackers to affect confidentiality via unknown vectors.
nvd
CVE-2010-0865P4MEDIUMCVSS 4.3v6.1.1.02010-04-13
CVE-2010-0865 [MEDIUM] CVE-2010-0865: Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle E-Busi Unspecified vulnerability in the Oracle Agile Engineering Data Management component in Oracle E-Business Suite 6.1.1.0 allows remote attackers to affect confidentiality via unknown vectors.
nvd
CVE-2014-4281P4MEDIUMCVSS 4.3v12.0.6v12.1.3+3 more2014-10-15
CVE-2014-4281 [MEDIUM] CVE-2014-4281: Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite Unspecified vulnerability in the Oracle Applications Framework component in Oracle E-Business Suite 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect integrity via unknown vectors related to Portal Integration.
nvd
Oracle E-Business Suite vulnerabilities | cvebase