Oracle E-Business Suite vulnerabilities
327 known vulnerabilities affecting oracle/e-business_suite.
Total CVEs
327
CISA KEV
1
actively exploited
Public exploits
5
Exploited in wild
1
Severity breakdown
CRITICAL54HIGH47MEDIUM184LOW42
Vulnerabilities
Page 2 of 17
CVE-2023-22076MEDIUMCVSS 6.1≥ 12.2.3, ≤ 12.2.122023-10-17
CVE-2023-22076 [MEDIUM] CVE-2023-22076: Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Pe
Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Personalization). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks require human interaction fr
nvd
CVE-2023-22093MEDIUMCVSS 6.5≥ 12.2.3, ≤ 12.2.122023-10-17
CVE-2023-22093 [MEDIUM] CVE-2023-22093: Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Requisition
Vulnerability in the Oracle iRecruitment product of Oracle E-Business Suite (component: Requisition and Vacancy). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iRecruitment. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2023-22004MEDIUMCVSS 4.3≥ 12.2.3, ≤ 12.2.122023-07-18
CVE-2023-22004 [MEDIUM] CVE-2023-22004: Vulnerability in the Oracle Applications Technology product of Oracle E-Business Suite (component: R
Vulnerability in the Oracle Applications Technology product of Oracle E-Business Suite (component: Reports Configuration). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications Technology. Successful attacks require human intera
nvd
CVE-2023-22035MEDIUMCVSS 6.1≥ 12.2.3, ≤ 12.2.122023-07-18
CVE-2023-22035 [MEDIUM] CWE-79 CVE-2023-22035: Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module)
Vulnerability in the Oracle Scripting product of Oracle E-Business Suite (component: iSurvey Module). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Scripting. Successful attacks require human interaction from a person other th
nvd
CVE-2023-21849HIGHCVSS 7.5≥ 12.2.3, ≤ 12.2.122023-01-18
CVE-2023-21849 [HIGH] CWE-284 CVE-2023-21849: Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Java uti
Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Java utils). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of this vulnerability can result in una
nvd
CVE-2023-21847MEDIUMCVSS 5.4≥ 12.2.3, ≤ 12.2.122023-01-18
CVE-2023-21847 [MEDIUM] CVE-2023-21847: Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Download). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks require hu
nvd
CVE-2022-21587CRITICALCVSS 9.8KEVPoC≥ 12.2.3, ≤ 12.2.112022-10-18
CVE-2022-21587 [CRITICAL] CWE-306 CVE-2022-21587: Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (
Vulnerability in the Oracle Web Applications Desktop Integrator product of Oracle E-Business Suite (component: Upload). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Web Applications Desktop Integrator. Successful attacks o
nvd
CVE-2022-21500HIGHCVSS 7.5PoCv12.22022-05-20
CVE-2022-21500 [HIGH] CVE-2022-21500: Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is
Vulnerability in Oracle E-Business Suite (component: Manage Proxies). The supported version that is affected is 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle E-Business Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access
nvd
CVE-2021-45105MEDIUMCVSS 5.9v12.22021-12-18
CVE-2021-45105 [MEDIUM] CWE-20 CVE-2021-45105: Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from u
Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups. This allows an attacker with control over Thread Context Map data to cause a denial of service when a crafted string is interpreted. This issue was fixed in Log4j 2.17.0, 2.12.3, and 2.3.1.
nvd
CVE-2019-10219MEDIUMCVSS 6.1≥ 12.2.3, ≤ 12.2.112019-11-08
CVE-2019-10219 [MEDIUM] CWE-79 CVE-2019-10219: A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properl
A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack.
nvd
CVE-2019-2551HIGHCVSS 8.2v12.1.1v12.1.2+7 more2019-04-23
CVE-2019-2551 [HIGH] CVE-2019-2551: Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponen
Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Print Server). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Ful
nvd
CVE-2019-2453CRITICALCVSS 9.1v12.1.1v12.1.2+1 more2019-01-16
CVE-2019-2453 [CRITICAL] CVE-2019-2453: Vulnerability in the Oracle Performance Management component of Oracle E-Business Suite (subcomponen
Vulnerability in the Oracle Performance Management component of Oracle E-Business Suite (subcomponent: Performance Management Plan). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Performance Management. Successful attacks
nvd
CVE-2019-2489CRITICALCVSS 9.1v12.1.3v12.2.3+5 more2019-01-16
CVE-2019-2489 [CRITICAL] CVE-2019-2489: Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponen
Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: OCM Query). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Succe
nvd
CVE-2019-2497HIGHCVSS 8.2v12.1.3v12.2.3+5 more2019-01-16
CVE-2019-2497 [HIGH] CVE-2019-2497: Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcompon
Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Messages). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Succes
nvd
CVE-2019-2498HIGHCVSS 8.2v12.1.1v12.1.2+7 more2019-01-16
CVE-2019-2498 [HIGH] CVE-2019-2498: Vulnerability in the Oracle Partner Management component of Oracle E-Business Suite (subcomponent: P
Vulnerability in the Oracle Partner Management component of Oracle E-Business Suite (subcomponent: Partner Dash board). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Partner Mana
nvd
CVE-2019-2470HIGHCVSS 8.2v12.1.1v12.1.2+7 more2019-01-16
CVE-2019-2470 [HIGH] CVE-2019-2470: Vulnerability in the Oracle Partner Management component of Oracle E-Business Suite (subcomponent: P
Vulnerability in the Oracle Partner Management component of Oracle E-Business Suite (subcomponent: Partner Detail). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Partner Manageme
nvd
CVE-2019-2400HIGHCVSS 8.2v12.1.1v12.1.2+7 more2019-01-16
CVE-2019-2400 [HIGH] CVE-2019-2400: Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: User Registra
Vulnerability in the Oracle iStore component of Oracle E-Business Suite (subcomponent: User Registration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iStore. Successful attack
nvd
CVE-2019-2440HIGHCVSS 8.2v12.1.1v12.1.2+7 more2019-01-16
CVE-2019-2440 [HIGH] CVE-2019-2440: Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: User Inter
Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Marketing. Successful att
nvd
CVE-2019-2492MEDIUMCVSS 4.7v12.1.1v12.1.2+7 more2019-01-16
CVE-2019-2492 [MEDIUM] CVE-2019-2492: Vulnerability in the Oracle Email Center component of Oracle E-Business Suite (subcomponent: Message
Vulnerability in the Oracle Email Center component of Oracle E-Business Suite (subcomponent: Message Display). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center. Succe
nvd
CVE-2019-2496MEDIUMCVSS 4.7v12.1.3v12.2.3+5 more2019-01-16
CVE-2019-2496 [MEDIUM] CVE-2019-2496: Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcompon
Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Messages). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Succ
nvd