Oracle E-Business Suite vulnerabilities

327 known vulnerabilities affecting oracle/e-business_suite.

Total CVEs
327
CISA KEV
1
actively exploited
Public exploits
5
Exploited in wild
1
Severity breakdown
CRITICAL54HIGH47MEDIUM184LOW42

Vulnerabilities

Page 3 of 17
CVE-2019-2485MEDIUMCVSS 4.7v12.1.1v12.1.2+7 more2019-01-16
CVE-2019-2485 [MEDIUM] CVE-2019-2485: Vulnerability in the Oracle Mobile Field Service component of Oracle E-Business Suite (subcomponent: Vulnerability in the Oracle Mobile Field Service component of Oracle E-Business Suite (subcomponent: Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Mobile Field
nvd
CVE-2019-2488MEDIUMCVSS 5.3v12.1.3v12.2.3+5 more2019-01-16
CVE-2019-2488 [MEDIUM] CVE-2019-2488: Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcompon Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Session Management). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Founda
nvd
CVE-2019-2396MEDIUMCVSS 4.7v12.1.3v12.2.3+5 more2019-01-16
CVE-2019-2396 [MEDIUM] CVE-2019-2396: Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcompon Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: Messages). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Succ
nvd
CVE-2019-2491MEDIUMCVSS 4.7v12.1.1v12.1.2+7 more2019-01-16
CVE-2019-2491 [MEDIUM] CVE-2019-2491: Vulnerability in the Oracle Email Center component of Oracle E-Business Suite (subcomponent: Message Vulnerability in the Oracle Email Center component of Oracle E-Business Suite (subcomponent: Message Display). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Email Center. Succe
nvd
CVE-2019-2546MEDIUMCVSS 4.3v12.1.1v12.1.2+7 more2019-01-16
CVE-2019-2546 [MEDIUM] CVE-2019-2546: Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: Vulnerability in the Oracle Applications Manager component of Oracle E-Business Suite (subcomponent: SQL Extensions). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7 and 12.2.8. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Applications
nvd
CVE-2018-2934MEDIUMCVSS 5.3v12.1.32018-07-18
CVE-2018-2934 [MEDIUM] CWE-665 CVE-2018-2934: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Attachments / File Upload). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successful attacks of thi
nvd
CVE-2018-2804HIGHCVSS 7.4v12.1.3v12.2.3+4 more2018-04-19
CVE-2018-2804 [HIGH] CVE-2018-2804: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: DB Privileges). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Suc
nvd
CVE-2018-2865MEDIUMCVSS 5.3v12.1.1v12.1.2+6 more2018-04-19
CVE-2018-2865 [MEDIUM] CVE-2018-2865: Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Conso Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Consolidation Hierarchy Viewer). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Le
nvd
CVE-2018-2864MEDIUMCVSS 5.3v12.1.3v12.2.3+4 more2018-04-19
CVE-2018-2864 [MEDIUM] CVE-2018-2864: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Diagnostics). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Succe
nvd
CVE-2018-2873MEDIUMCVSS 5.3v12.1.1v12.1.2+6 more2018-04-19
CVE-2018-2873 [MEDIUM] CVE-2018-2873: Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Accou Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Account Hierarchy Manager). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Ledger.
nvd
CVE-2018-2872MEDIUMCVSS 5.3v12.1.1v12.1.2+6 more2018-04-19
CVE-2018-2872 [MEDIUM] CVE-2018-2872: Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Accou Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Account Hierarchy Manager). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Ledger.
nvd
CVE-2018-2874MEDIUMCVSS 4.3v12.1.32018-04-19
CVE-2018-2874 [MEDIUM] CVE-2018-2874: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Logging). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows physical access to compromise Oracle Application Object Library. Successful attacks require human interaction from a person other than the attacker. Succe
nvd
CVE-2018-2867MEDIUMCVSS 5.3v12.1.3v12.2.3+4 more2018-04-19
CVE-2018-2867 [MEDIUM] CVE-2018-2867: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Diagnostics). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Succe
nvd
CVE-2018-2866MEDIUMCVSS 5.3v12.1.1v12.1.2+6 more2018-04-19
CVE-2018-2866 [MEDIUM] CVE-2018-2866: Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Conso Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Consolidation Hierarchy Viewer). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Le
nvd
CVE-2018-2656CRITICALCVSS 9.1v12.1.1v12.1.2+6 more2018-01-18
CVE-2018-2656 [CRITICAL] CVE-2018-2656: Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Data Vulnerability in the Oracle General Ledger component of Oracle E-Business Suite (subcomponent: Data Manager Server). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle General Ledger. Succ
nvd
CVE-2018-2635MEDIUMCVSS 4.8v12.1.3v12.2.3+4 more2018-01-18
CVE-2018-2635 [MEDIUM] CVE-2018-2635: Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomp Vulnerability in the Oracle Application Object Library component of Oracle E-Business Suite (subcomponent: Login). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Application Object Library. Successfu
nvd
CVE-2018-2684MEDIUMCVSS 4.9v12.1.3v12.2.3+4 more2018-01-18
CVE-2018-2684 [MEDIUM] CVE-2018-2684: Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: Regi Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: Registration Process). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5, 12.2.6 and 12.2.7. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle User Management. Successful attacks
nvd
CVE-2017-3515MEDIUMCVSS 5.4v12.1.3v12.2.3+3 more2017-04-24
CVE-2017-3515 [MEDIUM] CVE-2017-3515: Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: User Vulnerability in the Oracle User Management component of Oracle E-Business Suite (subcomponent: User Name/Password Management). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle User Management. Successful atta
nvd
CVE-2016-3520MEDIUMCVSS 4.9v12.1.3v12.2.3+2 more2016-07-21
CVE-2016-3520 [MEDIUM] CVE-2016-3520: Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Su Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote administrators to affect confidentiality via vectors related to AOL Diagnostic tests.
nvd
CVE-2016-3524MEDIUMCVSS 5.4v12.1.3v12.2.3+2 more2016-07-21
CVE-2016-3524 [MEDIUM] CVE-2016-3524: Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Unspecified vulnerability in the Oracle Applications Technology Stack component in Oracle E-Business Suite 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect confidentiality and integrity via vectors related to Configuration.
nvd