cbcvebase.

Oracle E-Business Suite vulnerabilities

345 known vulnerabilities affecting oracle/e-business_suite.

Total CVEs
345
CISA KEV
2
actively exploited
Public exploits
6
Exploited in wild
5
Severity breakdown
CRITICAL56HIGH56MEDIUM191LOW42

Vulnerabilities

Page 2 of 18
CVE-2026-46818P3HIGHCVSS 7.4≥ 12.2.3, ≤ 12.2.152026-05-28
CVE-2026-46818 [HIGH] CWE-284 CVE-2026-46818: Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmissio Vulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Payments. Successful attacks of this vulnerability can result in unauthori
nvd
CVE-2015-4798P3CRITICALCVSS 10.0v11.5.10.22015-10-21
CVE-2015-4798 [CRITICAL] CVE-2015-4798: Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to DB Listener, a different vulnerability than CVE-2015-4839.
nvd
CVE-2025-21516P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.132025-01-21
CVE-2025-21516 [HIGH] CWE-863 CVE-2025-21516: Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Service Req Vulnerability in the Oracle Customer Care product of Oracle E-Business Suite (component: Service Requests). Supported versions that are affected are 12.2.5-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Customer Care. Successful attacks of this vulnerability can result in unau
nvd
CVE-2024-21279P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.132024-10-15
CVE-2024-21279 [HIGH] CWE-863 CVE-2024-21279: Vulnerability in the Oracle Sourcing product of Oracle E-Business Suite (component: Auctions). Supp Vulnerability in the Oracle Sourcing product of Oracle E-Business Suite (component: Auctions). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Sourcing. Successful attacks of this vulnerability can result in unauthorized creation,
nvd
CVE-2024-21282P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.132024-10-15
CVE-2024-21282 [HIGH] CWE-863 CVE-2024-21282: Vulnerability in the Oracle Financials product of Oracle E-Business Suite (component: Common Compone Vulnerability in the Oracle Financials product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Financials. Successful attacks of this vulnerability can result in unauthori
nvd
CVE-2024-21278P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.132024-10-15
CVE-2024-21278 [HIGH] CWE-863 CVE-2024-21278: Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Busi Vulnerability in the Oracle Contract Lifecycle Management for Public Sector product of Oracle E-Business Suite (component: Award Processes). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Contract Lifecycle Management for Public
nvd
CVE-2024-21265P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.132024-10-15
CVE-2024-21265 [HIGH] CWE-863 CVE-2024-21265: Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Site Hierarchy F Vulnerability in the Oracle Site Hub product of Oracle E-Business Suite (component: Site Hierarchy Flows). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Site Hub. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2024-21269P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.132024-10-15
CVE-2024-21269 [HIGH] CWE-863 CVE-2024-21269: Vulnerability in the Oracle Incentive Compensation product of Oracle E-Business Suite (component: Co Vulnerability in the Oracle Incentive Compensation product of Oracle E-Business Suite (component: Compensation Plan). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Incentive Compensation. Successful attacks of this vulnerability
nvd
CVE-2024-21266P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.132024-10-15
CVE-2024-21266 [HIGH] CWE-863 CVE-2024-21266: Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Price Li Vulnerability in the Oracle Advanced Pricing product of Oracle E-Business Suite (component: Price List). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Pricing. Successful attacks of this vulnerability can result in unau
nvd
CVE-2024-21267P3HIGHCVSS 8.1≥ 12.2.12, ≤ 12.2.132024-10-15
CVE-2024-21267 [HIGH] CWE-863 CVE-2024-21267: Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Plan Vulnerability in the Oracle Cost Management product of Oracle E-Business Suite (component: Cost Planning). Supported versions that are affected are 12.2.12-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Cost Management. Successful attacks of this vulnerability can result in un
nvd
CVE-2024-21268P3HIGHCVSS 8.1≥ 12.2.11, ≤ 12.2.132024-10-15
CVE-2024-21268 [HIGH] CWE-863 CVE-2024-21268: Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Diag Vulnerability in the Oracle Applications Manager product of Oracle E-Business Suite (component: Diagnostics). Supported versions that are affected are 12.2.11-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Manager. Successful attacks of this vulnerability can resu
nvd
CVE-2024-21271P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.132024-10-15
CVE-2024-21271 [HIGH] CWE-863 CVE-2024-21271: Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Field Servi Vulnerability in the Oracle Field Service product of Oracle E-Business Suite (component: Field Service Engineer Portal). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Field Service. Successful attacks of this vulnerability can r
nvd
CVE-2024-21275P3HIGHCVSS 8.1≥ 12.2.7, ≤ 12.2.132024-10-15
CVE-2024-21275 [HIGH] CWE-863 CVE-2024-21275: Vulnerability in the Oracle Quoting product of Oracle E-Business Suite (component: User Interface). Vulnerability in the Oracle Quoting product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.7-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Quoting. Successful attacks of this vulnerability can result in unauthorized creati
nvd
CVE-2024-21088P3HIGHCVSS 7.5≥ 12.2.4, ≤ 12.2.122024-04-16
CVE-2024-21088 [HIGH] CWE-444 CVE-2024-21088: Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Imp Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Import Utility). Supported versions that are affected are 12.2.4-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Production Scheduling. Successful attacks of this vulnerability can
nvd
CVE-2015-4839P3CRITICALCVSS 10.0v11.5.10.22015-10-21
CVE-2015-4839 [CRITICAL] CVE-2015-4839: Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to DB Listener, a different vulnerability than CVE-2015-4798.
nvd
CVE-2025-21506P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.132025-01-21
CVE-2025-21506 [HIGH] CWE-863 CVE-2025-21506: Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Techno Vulnerability in the Oracle Project Foundation product of Oracle E-Business Suite (component: Technology Foundation). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Foundation. Successful attacks of this vulnerability can
nvd
CVE-2024-21276P3HIGHCVSS 8.1≥ 12.2.3, ≤ 12.2.132024-10-15
CVE-2024-21276 [HIGH] CWE-863 CVE-2024-21276: Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Messages) Vulnerability in the Oracle Work in Process product of Oracle E-Business Suite (component: Messages). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Work in Process. Successful attacks of this vulnerability can result in unauthor
nvd
CVE-2024-21270P3HIGHCVSS 8.1≥ 12.2.6, ≤ 12.2.132024-10-15
CVE-2024-21270 [HIGH] CWE-863 CVE-2024-21270: Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (compone Vulnerability in the Oracle Common Applications Calendar product of Oracle E-Business Suite (component: Tasks). Supported versions that are affected are 12.2.6-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Common Applications Calendar. Successful attacks of this vulnerability
nvd
CVE-2023-21849P3HIGHCVSS 7.5≥ 12.2.3, ≤ 12.2.122023-01-18
CVE-2023-21849 [HIGH] CWE-284 CVE-2023-21849: Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Java uti Vulnerability in the Oracle Applications DBA product of Oracle E-Business Suite (component: Java utils). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications DBA. Successful attacks of this vulnerability can result in una
nvd
CVE-2018-2804P3HIGHCVSS 7.4v12.1.3v12.2.3+4 more2018-04-19
CVE-2018-2804 [HIGH] CVE-2018-2804: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: DB Privileges). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Suc
nvd
Oracle E-Business Suite vulnerabilities | cvebase